Cogent Real-Time Systems Vulnerabilities
Multiple Cogent real-time data acquisition and integration products contain input validation, error handling, and access control flaws (CWE-20, CWE-755, CWE-763) that could allow an attacker to execute arbitrary code or bypass security controls. Affected products include Cogent DataHub (v7.2.2 and earlier), OPC DataHub (v6.4.21 and earlier), Cascade DataHub for Windows (v6.4.21 and earlier), and DataSim/DataPid demonstration clients. These products are used for real-time data collection, process monitoring, and integration with SCADA and HMI systems in industrial control environments. No vendor patches are available for these vulnerabilities.
- Network access to Cogent DataHub, OPC DataHub, or Cascade DataHub services (typically port 4502 or related DataHub ports)
- No authentication required to send malformed input to the vulnerable service
Patching may require device reboot — plan for process interruption
/api/v1/advisories/7a1acb6e-6787-417d-92b6-3fabca4fa1aeGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.