PatchSiren

PatchSiren cyber security CVE debrief

CVE-2020-28168 Subnet Solutions Inc. CVE debrief

CVE-2020-28168 is a Server-Side Request Forgery (SSRF) vulnerability affecting Subnet Solutions Inc. PowerSYSTEM Center versions up to and including PSC_2020_v5.21.x. The vulnerability stems from the product's use of Axios NPM package version 0.21.0, which contains an SSRF flaw allowing attackers to bypass proxy restrictions by providing a URL that redirects to a restricted host or IP address. Published by CISA on October 1, 2024, this advisory addresses a vulnerability in industrial control systems software used for power system management. The CVSS 3.1 score of 5.9 (Medium severity) reflects network attack vector with high attack complexity, no required privileges or user interaction, and high confidentiality impact. The vulnerability enables attackers to potentially access internal resources that should be protected by proxy controls. Subnet Solutions Inc. has released PowerSYSTEM Center 2020 Update 22 to address this issue. Users unable to immediately update should implement network segmentation controls to limit outbound connection requests from the PowerSYSTEM Center security zone to external websites, and may disable usage of previous UI extensions as an additional compensating control.

Vendor
Subnet Solutions Inc.
Product
PowerSYSTEM Center
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2022-09-13
Original CVE updated
2022-09-13
Advisory published
2022-09-13
Advisory updated
2022-09-13

Who should care

Organizations operating Subnet Solutions Inc. PowerSYSTEM Center for power system management and industrial control, particularly those in critical infrastructure sectors including energy and utilities. Security teams responsible for ICS/OT environments, network administrators managing proxy configurations, and compliance officers overseeing industrial cybersecurity standards should prioritize assessment and remediation.

Technical summary

CVE-2020-28168 is an SSRF vulnerability in PowerSYSTEM Center's use of Axios 0.21.0. Attackers can bypass proxy restrictions by supplying URLs that redirect to restricted internal hosts or IP addresses. The vulnerability requires network access but no authentication. Affected versions are PSC_2020_v5.21.x and earlier. Fixed in 2020 Update 22.

Defensive priority

medium

Recommended defensive actions

  • Update PowerSYSTEM Center to version 2020 Update 22 or later, available through Settings > Overview > Version in the application interface
  • If immediate patching is not feasible, limit outbound connection requests from the PowerSYSTEM Center security zone to external websites
  • Disable usage of previous UI extensions as a compensating control where updates cannot be applied promptly
  • Contact Subnet Solutions Customer Service for assistance with update procedures or technical support
  • Apply network segmentation to isolate PowerSYSTEM Center from untrusted networks
  • Monitor for anomalous outbound connection attempts from PowerSYSTEM Center systems

Evidence notes

The vulnerability exists in PowerSYSTEM Center versions <=PSC_2020_v5.21.x due to inclusion of Axios NPM package 0.21.0. CISA's CSAF advisory confirms affected product identification as CSAFPID-0001. The SSRF mechanism involves redirect-based proxy bypass.

Sources and references

Verified primary and authoritative sources

  • CVE-2020-28168 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2020-28168

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2020-28168 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2020-28168

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-277-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-277-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.