Public advisories disclosed two root-level remote code execution vulnerabilities in atvise SCADA 3.13.0 from atvise GmbH / Bachmann Visutec, affecting deployments with the WEBACCESS module enabled. One flaw allows pre-authentication compromise through an OPC UA authentication bypass on port 4840, which can be chained with WebMI script tampering and anonymous request paths to execute arbitrary commands as root. The second issue is an authenticated default-credential RCE in WebHMI/WebMI, where a built-in root account ships with an empty password and a login branch can grant a superuser session without proper password verification while that default state remains.
Researchers said successful exploitation can lead to complete host compromise, including arbitrary command execution, file access, and manipulation of SCADA control logic and node values. The advisory noted that WEBACCESS is normally loaded in licensed production deployments, increasing practical exposure, and said proof-of-concept code and full technical analysis were released publicly through Full Disclosure and separate write-ups covering the OPC UA unauthenticated attack path and the WebMI default-credential RCE.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On 0day Rubbish's site, the researchers published advisories covering two atvise SCADA 3.13.0 remote code execution issues: an unauthenticated OPC UA auth-bypass-to-root RCE and a default-credential authenticated root RCE. The publication included technical analysis and proof-of-concept material.
The two atvise SCADA 3.13.0 vulnerabilities were publicly disclosed through the Full Disclosure mailing list archives. The posting described complete root compromise impact and noted that proof-of-concept code and full analysis were publicly available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open source0day-rubbish.com
Open source0day-rubbish.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.