{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-104628", "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "state": "PUBLISHED", "assignerShortName": "icscert", "dateReserved": "2026-10-05T21:19:46.307Z", "datePublished": "2026-10-08T21:24:25.763Z", "dateUpdated": "2026-10-09T13:21:41.667Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "shortName": "icscert", "dateUpdated": "2026-10-08T21:24:25.763Z" }, "title": "Satel Netco Design Inefficient Regular Expression Complexity", "datePublic": "2026-10-08T15:00:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-1333", "description": "CWE-1333 Inefficient Regular Expression Complexity", "type": "CWE" } ] } ], "affected": [ { "vendor": "Satel", "product": "Satel Netco Design", "versions": [ { "status": "affected", "version": "0", "lessThan": "v2.1.7", "versionType": "custom" }, { "status": "unaffected", "version": "v2.1.7" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Satel Netco Design versions prior to v2.1.7 contains an inefficient regular expression complexity vulnerability. An authenticated user with Viewer privileges could submit crafted search input that causes excessive processing, potentially degrading the availability of the application.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Satel Netco Design versions prior to v2.1.7 contains an inefficient regular expression complexity vulnerability. An authenticated user with Viewer privileges could submit crafted search input that causes excessive processing, potentially degrading the availability of the application." } ] } ], "references": [ { "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03" }, { "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-03.json" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "NONE", "subConfidentialityImpact": "NONE", "vulnIntegrityImpact": "NONE", "subIntegrityImpact": "NONE", "vulnAvailabilityImpact": "HIGH", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "HIGH", "baseScore": 7.1, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" } }, { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH", "baseSeverity": "MEDIUM", "baseScore": 6.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } } ], "solutions": [ { "lang": "en", "value": "Satel advises users to update to Satel Netco Design v2.1.7.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Satel advises users to update to Satel Netco Design v2.1.7." } ] } ], "credits": [ { "lang": "en", "value": "Alex Williams of Pellera Technologies reported this vulnerability to CISA.", "type": "finder" } ], "source": { "advisory": "ICSA-26-281-03", "discovery": "EXTERNAL" }, "x_generator": { "engine": "Vulnogram 1.0.5" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-09T13:21:32.261306Z", "id": "CVE-2026-104628", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-09T13:21:41.667Z" } } ] } }