Back to Labs
Security Advisory

CVE-2023-28343

About

OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.

Weakness (CWE):CWE-78

Rainforest analyst review

Altenergy Power Control Software (the APsystems Energy Communication Unit) has an OS command injection: shell metacharacters in the timezone parameter of index.php/management/set_timezone flow through set_timezone in the management model into a shell. Unauthenticated and remote, a crafted request yields command execution on the device, full control of an energy communication unit with no login required.

This sits at the IT/OT boundary in solar energy deployments, and unauthenticated command injection on internet-reachable energy gear is exactly what opportunistic botnets and, increasingly, actors interested in disrupting distributed energy resources go looking for. Proof-of-concept traffic for a clean, unauthenticated one-request injection like this tends to appear fast and hit every reachable unit indiscriminately. The 9.8 is fully earned.

Our controlling factor is internet reachability. We would hunt for any APsystems ECU exposed to untrusted networks, pull the management interface off the public internet, and segment these units away from both IT and the wider internet. Since the payload is a specific parameter on a specific path, a virtual-patch rule blocking metacharacters into set_timezone is a viable stopgap while firmware remediation is worked out on OT timelines.

References

Related CVEs

Frequently asked questions

What is CVE-2023-28343?

OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.

How severe is CVE-2023-28343?

CVE-2023-28343 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2023-28343 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2023-28343?

Public advisories list the following as affected: energy communication unit, energy communication unit firmware. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2023-28343?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email