CISA Releases 20 ICS Advisories Detailing Vulnerabilities & Exploits

Vulnerabilities in the SIPROTEC 5 series include Cleartext storage of sensitive information (CVE-2024-53651), which has a CVSS v3 base score of 4.6. Mitigation involves firmware updates and restricting network access. This SCADA management software contains vulnerabilities including  OS Command Injection CVE-2025-25067, Missing Authentication for Critical Function CVE-2025-24865, Cleartext Storage of Sensitive Information CVE-2025-22896 , Cross-Site Request Forgery (CSRF) CVE-2025-23411. This advisory highlights Observable Discrepancy (CVE-2023-37482) across the broader SIMATIC product line with a CVSS v3 base score of 5.3. Siemens recommends applying security patches and isolating devices from external networks. CISA urges all users, administrators, and organizations relying on these ICS products to review the advisories thoroughly, apply vendor-recommended patches, and implement robust security measures such as network segmentation and strong authentication protocols to mitigate risks effectively. The RUGGEDCOM APE1808 networking devices are vulnerable to DoS condition, machine-in-the middle attack (MITM), escalate privileges, execute unauthorized code, and access unauthorized systems and information. Vulnerability in SIPROTEC 5 devices could allow an unauthenticated, remote attacker to retrieve sensitive information of the device tracked as (CVE-2024-54015). A few vulnerabilities include improper restriction of communication channels to intended endpoints, improper resource shutdown or Release, inadequate encryption strength, and race condition. This advisory addresses vulnerabilities in Siemens’ widely used programmable logic controllers (PLCs) which includes improper resource shutdown or release (CVE-2022-38465) and improper validation of syntactic correctness of input (CVE-2025-24811). Although primarily a medical IoT device, this advisory highlights risks such as exposure of private personal information to an unauthorized actor CVE-2025-20615, uncaught exception CVE-2025-24836 and files or directories accessible to external parties CVE-2025-23421. These vulnerabilities could enable an attacker to execute remote code or allow a malicious site administrator to change passwords for users. Questa and ModelSim simulation tools are affected by vulnerabilities tracked as CVE-2024-53977, Uncontrolled search path element causing elevation of privileges. Siemens Teamcenter, a product lifecycle management software, contains a flaw tracked as CVE-2025-23363 Url Redirection to an untrusted site (‘open Redirect’). Dingtian DT-R0 series devices have been identified with authentication Bypass Using an Alternate Path or Channel tracked as CVE-2025-1283. These monitoring tools for industrial PCs have vulnerability tracked as CVE-2025-23403, incorrect permission assignment for critical resource causing privilege escalation. Use of GET request method with sensitive Query Strings CVE-2025-26473, exposure of sensitive information to an unauthorized actor CVE-2025-25281, command injection CVE-2025-24861.

This Cyber News was published on cybersecuritynews.com. Publication date: Fri, 14 Feb 2025 13:40:12 +0000


Cyber News related to CISA Releases 20 ICS Advisories Detailing Vulnerabilities & Exploits

Threat landscape for industrial automation systems. H2 2023 - In the second half of 2023, the percentage of ICS computers on which malicious objects were blocked decreased by 2.1 pp to 31.9%. Percentage of ICS computers on which malicious objects were blocked, by half year. In H2 2023, building automation once ...
1 year ago Securelist.com
CISA adds Check Point Quantum Security Gateways and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog - CISA adds Apache Flink flaw to its Known Exploited Vulnerabilities catalog. CISA adds D-Link DIR router flaws to its Known Exploited Vulnerabilities catalog. CISA adds Google Chrome zero-days to its Known Exploited Vulnerabilities catalog. CISA adds ...
9 months ago Securityaffairs.com
Threat landscape for industrial automation systems, Q1 2024 - In the first quarter of 2024, the percentage of ICS computers on which malicious objects were blocked decreased by 0.3 pp from the previous quarter to 24.4%. Compared to the first quarter of 2023, the percentage decreased by 1.3 pp. Percentage of ICS ...
9 months ago Securelist.com
CVE-2021-36845 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) versions < 1.3.8, there are 46 vulnerable parameters that were missed by the vendor while patching the 1.3.7 version to 1.3.8. ...
3 years ago
Optigo Networks ONS-S8 Spectra Aggregation Switch | CISA - CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial ...
5 months ago Cisa.gov CVE-2024-41925 CVE-2024-45367
Siemens SCALANCE and RUGGEDCOM M-800/S615 Family - As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT ...
1 year ago Cisa.gov CVE-2023-44317 CVE-2023-49692
Delta Electronics InfraSuite Device Master - RISK EVALUATION. Successful exploitation of this vulnerability could allow remote code execution. Delta Electronics InfraSuite Device Master contains a deserialization of untrusted data vulnerability because it runs a version of Apache ActiveMQ which ...
10 months ago Cisa.gov CVE-2023-46604
Mitsubishi Electric GX Works2 - RISK EVALUATION. Successful exploitation of these vulnerabilities could allow a Denial-of-service due to improper input validation in the simulation function of GX Works2 by sending specially crafted packets. An attacker may be able to cause ...
1 year ago Cisa.gov CVE-2023-5274 CVE-2023-5275
Mitsubishi Electric FA Engineering Software Products - RISK EVALUATION. Successful exploitation of these vulnerabilities could allow a malicious attacker to disclose information in the affected products. For the correspondence table of the affected products and each vulnerability, refer to Mitsubishi ...
1 year ago Cisa.gov CVE-2022-21151 CVE-2021-33149
Delta Electronics DOPSoft - RISK EVALUATION. Successful exploitation of this vulnerability could lead to remote code execution. The affected product is vulnerable to a stack-based buffer overflow, which may allow for arbitrary code execution if an attacker can lead a legitimate ...
1 year ago Cisa.gov CVE-2023-5944
Mitsubishi Electric FA Engineering Software Products - RISK EVALUATION. Successful exploitation of this vulnerability could allow a malicious attacker to execute malicious code by tricking legitimate users to open a specially crafted project file, which could result in information disclosure, tampering ...
1 year ago Cisa.gov CVE-2023-5247
WAGO PFC200 Series - RISK EVALUATION. Successful exploitation of this vulnerability could allow an attacker with administrative privileges to access sensitive files in an unintended, undocumented way. Compact Controller CC100: Versions later than FW19, up to and ...
1 year ago Cisa.gov CVE-2023-4089
Mitsubishi Electric Electrical Discharge Machines - RISK EVALUATION. Successful exploitation of this vulnerability could allow an attacker to disclose, tamper with, destroy or delete information in the products, or cause a denial-of-service condition on the products. Remote code execution ...
1 year ago Cisa.gov CVE-2023-21554
PTC KEPServerEx - EXECUTIVE SUMMARY CVSS v3 9.1 ATTENTION: Exploitable remotely/low attack complexity. RISK EVALUATION. Successful exploitation of these vulnerabilities could allow an attacker gaining Windows SYSTEM-level code execution on the service host and may ...
1 year ago Cisa.gov CVE-2023-5908 CVE-2023-5909
Delta Electronics InfraSuite Device Master - RISK EVALUATION. Successful exploitation of these vulnerabilities could allow an attacker to remotely execute arbitrary code and obtain plaintext credentials. In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows ...
1 year ago Cisa.gov CVE-2023-46690 CVE-2023-47207 CVE-2023-39226 CVE-2023-47279
Fuji Electric Tellus Lite V-Simulator - RISK EVALUATION. Successful exploitation of these vulnerabilities could crash the device being accessed, allow remote code execution, or overwrite files. Stack-based buffer overflow may occur when Fuji Electric Tellus Lite V-Simulator parses a ...
1 year ago Cisa.gov CVE-2023-35127 CVE-2023-40152 CVE-2023-5299
EFACEC BCU 500 - RISK EVALUATION. Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product or compromise the web application through a cross-site request forgery vulnerability. Through the ...
1 year ago Cisa.gov CVE-2023-50707 CVE-2023-6689
Cyber Insights 2023: ICS and Operational Technology - The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs. At the same time, ICS/OT is facing an expanding attack surface caused by ...
2 years ago Securityweek.com
Yokogawa STARDOM - RISK EVALUATION. Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service condition to the FCN/FCJ controller by sending a specially crafted packet. This vulnerability may allow to a remote attacker to ...
1 year ago Cisa.gov CVE-2023-5915
Franklin Electric Fueling Systems Colibri - RISK EVALUATION. Successful exploitation of this vulnerability could allow an attacker to obtain login credentials for other users. The discontinued FFS Colibri product allows a remote user to access files on the system including files containing ...
1 year ago Cisa.gov CVE-2023-5885
Schweitzer Engineering Laboratories SEL-411L - RISK EVALUATION. Successful exploitation of this vulnerability could expose authorized users to clickjacking attacks. An Improper Restriction of Rendered UI Layers or Frames in the Schweitzer Engineering Laboratories SEL-411L could allow an ...
1 year ago Cisa.gov CVE-2023-2265
Johnson Controls Metasys and Facility Explorer - RISK EVALUATION. Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service by sending invalid credentials. Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of ...
1 year ago Cisa.gov CVE-2023-4486
ControlbyWeb Relay - RISK EVALUATION. Successful exploitation of this vulnerability could allow an authenticated attacker to run malicious code during a user's session. The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting ...
1 year ago Cisa.gov CVE-2023-6333
Subnet Solutions Inc. PowerSYSTEM Center - RISK EVALUATION. Successful exploitation of this vulnerability could result in an attacker achieving arbitrary code execution and privilege escalation through the unquoted service path. Subnet Solutions PowerSYSTEM Center versions 2020 v5.0.x through ...
1 year ago Cisa.gov CVE-2023-6631
Franklin Fueling System EVO 550/5000 - RISK EVALUATION. Successful exploitation of this vulnerability could allow an attacker to read arbitrary files on the system. Franklin Fueling System EVO 550 and EVO 5000 are vulnerable to a Path Traversal vulnerability that could allow an attacker ...
1 year ago Cisa.gov CVE-2024-2442

Latest Cyber News


Cyber Trends (last 7 days)