Q2BSTUDIO is a technology development and services company that specializes in helping its clients protect their systems and data against vulnerabilities. On this occasion, vulnerabilities were detected in the PowerSYSTEM Center (PSC) 2020 product from Subnet Solutions Inc., which could be exploited by an attacker to cause a denial of service.
The identified vulnerabilities are of the Out-of-Bounds Read and Deserialization of Untrusted Data type, affecting versions 5.24.x and earlier of PowerSYSTEM Center 2020. Subnet Solutions Inc. recommends updating to the latest versions of the product, such as PSC 2020 Update 25 and PSC 2024, to mitigate the risk.
If unable to update, it is suggested to disable vulnerable services, configure network firewalls, and maintain strict control over administrator access to the system. For assistance with updates, you can contact Subnet Solutions Inc. directly via email at support@subnet.com.
CISA also recommends taking additional defensive measures to minimize the risk of exploitation of these vulnerabilities, such as limiting the exposure of control system devices to the network and keeping remote access methods, such as VPNs, up to date. Likewise, it is advised to implement recommended cybersecurity strategies to actively defend industrial control system assets.





