PatchSiren cyber security CVE debrief
CVE-2020-28168 Subnet Solutions Inc. CVE debrief
CVE-2020-28168 is a Server-Side Request Forgery (SSRF) vulnerability affecting Subnet Solutions Inc. PowerSYSTEM Center versions up to and including PSC_2020_v5.21.x. The vulnerability stems from the product's use of Axios NPM package version 0.21.0, which contains an SSRF flaw allowing attackers to bypass proxy restrictions by providing a URL that redirects to a restricted host or IP address. Published by CISA on October 1, 2024, this advisory addresses a vulnerability in industrial control systems software used for power system management. The CVSS 3.1 score of 5.9 (Medium severity) reflects network attack vector with high attack complexity, no required privileges or user interaction, and high confidentiality impact. The vulnerability enables attackers to potentially access internal resources that should be protected by proxy controls. Subnet Solutions Inc. has released PowerSYSTEM Center 2020 Update 22 to address this issue. Users unable to immediately update should implement network segmentation controls to limit outbound connection requests from the PowerSYSTEM Center security zone to external websites, and may disable usage of previous UI extensions as an additional compensating control.
- Vendor
- Subnet Solutions Inc.
- Product
- PowerSYSTEM Center
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2022-09-13
- Original CVE updated
- 2022-09-13
- Advisory published
- 2022-09-13
- Advisory updated
- 2022-09-13
Who should care
Organizations operating Subnet Solutions Inc. PowerSYSTEM Center for power system management and industrial control, particularly those in critical infrastructure sectors including energy and utilities. Security teams responsible for ICS/OT environments, network administrators managing proxy configurations, and compliance officers overseeing industrial cybersecurity standards should prioritize assessment and remediation.
Technical summary
CVE-2020-28168 is an SSRF vulnerability in PowerSYSTEM Center's use of Axios 0.21.0. Attackers can bypass proxy restrictions by supplying URLs that redirect to restricted internal hosts or IP addresses. The vulnerability requires network access but no authentication. Affected versions are PSC_2020_v5.21.x and earlier. Fixed in 2020 Update 22.
Defensive priority
medium
Recommended defensive actions
- Update PowerSYSTEM Center to version 2020 Update 22 or later, available through Settings > Overview > Version in the application interface
- If immediate patching is not feasible, limit outbound connection requests from the PowerSYSTEM Center security zone to external websites
- Disable usage of previous UI extensions as a compensating control where updates cannot be applied promptly
- Contact Subnet Solutions Customer Service for assistance with update procedures or technical support
- Apply network segmentation to isolate PowerSYSTEM Center from untrusted networks
- Monitor for anomalous outbound connection attempts from PowerSYSTEM Center systems
Evidence notes
The vulnerability exists in PowerSYSTEM Center versions <=PSC_2020_v5.21.x due to inclusion of Axios NPM package 0.21.0. CISA's CSAF advisory confirms affected product identification as CSAFPID-0001. The SSRF mechanism involves redirect-based proxy bypass.
Sources and references
Verified primary and authoritative sources
-
CVE-2020-28168 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2020-28168
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2020-28168 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-28168
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-277-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-277-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.