Columbia Weather Systems MicroServer
Act Now9.8ICS-CERT ICSA-19-078-02Mar 19, 2019
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Columbia Weather Systems MicroServer firmware versions MS_2.6.9900 and earlier contain multiple vulnerabilities (CWE-79 cross-site scripting, CWE-22 path traversal, CWE-287 authentication bypass, CWE-20 improper input validation, CWE-94 code injection). These flaws allow unauthenticated, remote attackers to disclose sensitive data, trigger denial-of-service conditions, and execute arbitrary code on the device. Columbia Weather Systems has released firmware version MS_2.7.9973 to address all identified issues.
What this means
What could happen
An attacker with network access to a Weather MicroServer could read sensitive data, crash the device to disrupt weather monitoring, or run arbitrary commands to alter operational parameters or inject malicious logic into the device.
Who's at risk
Water utilities and municipal electric systems that use Columbia Weather Systems MicroServer for weather monitoring and environmental input to SCADA or control logic. Any facility relying on weather data for operational decisions (precipitation monitoring, wind speed for tower loads, temperature for demand forecasting) is affected.
How it could be exploited
An attacker on the network (or Internet if the device is exposed) sends a crafted request to the MicroServer. The device fails to validate input or authenticate the request properly, allowing the attacker to trigger path traversal, code injection, or denial-of-service conditions without needing valid credentials.
Prerequisites
- Network access to the Weather MicroServer (IP address and accessible port)
- Device firmware version MS_2.6.9900 or earlier
- No authentication required for exploitation
Remotely exploitableNo authentication requiredLow complexityHigh CVSS (9.8)Affects operational monitoring systemsDefault network exposure risk
Exploitability
Moderate exploit probability (EPSS 1.1%)
Affected products (1)
ProductAffected VersionsFix Status
Weather MicroServer: firmware≤ MS 2.6.9900MS_2.7.9973
Remediation & Mitigation
0/4
Do now
0/2WORKAROUNDBlock network access to Weather MicroServer from the Internet; ensure device is not exposed on public IPs
HARDENINGPlace Weather MicroServer behind a firewall and isolate from business network
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXUpgrade Weather MicroServer firmware to MS_2.7.9973 or later
HARDENINGIf remote access is required, use a VPN connection and keep VPN software updated
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/6c0db0fa-15ae-4d74-bf36-4825b18e2294