Historical snapshot · Cybersecurity

CISA Advisories

Cybersecurity advisories and mitigation guidance for networks and critical infrastructure.

This page is an archived snapshot of the CISA Advisories feed collected on Jan 15, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
30 recordsOfficial source · JSON
· CISA Cybersecurity Advisory

Secure Connectivity Principles for Operational Technology (OT)

CISA and the UK National Cyber Security Centre (NCSC-UK), in collaboration with federal and international partners, have released Secure Connectivity Principles for Operational Technology (OT) guidance to help asset owners address increasing business and regulatory pressures for connectivity into operational technology (OT) networks. This guidance outlines eight principles to use as a framework to design, secure,…
Read full source summary
CISA and the UK National Cyber Security Centre (NCSC-UK), in collaboration with federal and international partners, have released Secure Connectivity Principles for Operational Technology (OT) guidance to help asset owners address increasing business and regulatory pressures for connectivity into operational technology (OT) networks. This guidance outlines eight principles to use as a framework to design, secure, and manage connectivity into OT environments. These principles are particularly critical for operators of essential services. Please share your thoughts! We welcome your feedback. CISA Product Survey
· CISA Cybersecurity Advisory

Rockwell Automation 432ES-IG3 Series A

View CSAF Summary Successful exploitation of this vulnerability could result in a denial-of-service condition. The following versions of Rockwell Automation 432ES-IG3 Series A are affected: 432ES-IG3 Series A (CVE-2025-9368) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 432ES-IG3 Series A Allocation of Resources Without Limits or Throttling Background Critical Infrastructure…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could result in a denial-of-service condition. The following versions of Rockwell Automation 432ES-IG3 Series A are affected: 432ES-IG3 Series A (CVE-2025-9368) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 432ES-IG3 Series A Allocation of Resources Without Limits or Throttling Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2025-9368 A security issue exists within 432ES-IG3 Series A, which affects GuardLink EtherNet/IP Interface, resulting in a denial-of-service condition. A manual power cycle is required to recover the device. View CVE Details Affected Products Rockwell Automation 432ES-IG3 Series A Vendor: Rockwell Automation Product Version: Rockwell Automation 432ES-IG3 Series A: V1.001 Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends users of 432ES-IG3 Series A update to V2.001.9 or later. The upgrade can be downloaded from the Rockwell Automation website. Mitigation Rockwell Automation users using the affected software, who are not able to upgrade to one of the corrected versions, should follow Rockwell Automation's security best practices. Mitigation For more information, please review Rockwell Automation's advisory. Relevant CWE: CWE-770 Allocation of Resources Without Limits or Throttling Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Acknowledgments Rockwell Automation reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-13 Date Revision Summary 2026-01-13 1 Initial Republication of Rockwell Automation advisory SD1764 Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Rockwell Automation FactoryTalk DataMosaix Private Cloud

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized sensitive database operations. The following versions of Rockwell Automation FactoryTalk DataMosaix Private Cloud are affected: FactoryTalk DataMosaix Private Cloud (CVE-2025-12807) FactoryTalk DataMosaix Private Cloud (CVE-2025-12807) FactoryTalk DataMosaix Private Cloud (CVE-2025-12807) CVSS Vendor…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized sensitive database operations. The following versions of Rockwell Automation FactoryTalk DataMosaix Private Cloud are affected: FactoryTalk DataMosaix Private Cloud (CVE-2025-12807) FactoryTalk DataMosaix Private Cloud (CVE-2025-12807) FactoryTalk DataMosaix Private Cloud (CVE-2025-12807) CVSS Vendor Equipment Vulnerabilities v3 8.8 Rockwell Automation Rockwell Automation FactoryTalk DataMosaix Private Cloud Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2025-12807 A security issue was discovered in DataMosaix Private Cloud, allowing users with low privilege to perform sensitive database operations through exposed Application Programming Interface (API) endpoints. View CVE Details Affected Products Rockwell Automation FactoryTalk DataMosaix Private Cloud Vendor: Rockwell Automation Product Version: Rockwell Automation FactoryTalk DataMosaix Private Cloud: 7.11, Rockwell Automation FactoryTalk DataMosaix Private Cloud: 8.00, Rockwell Automation FactoryTalk DataMosaix Private Cloud: 8.01 Product Status: known_affected Remediations Mitigation Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible: Vendor fix Update FactoryTalk DataMosaix Private Cloud to Version 8.01.02 or later. Mitigation Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's best security practices. Relevant CWE: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Acknowledgments Rockwell Automation reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-13 Date Revision Summary 2026-01-13 1 Initial republication of Rockwell Automation advisory 'FactoryTalk DataMosaix Private Cloud SQL Injection' Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20805 Microsoft Windows Information Disclosure Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20805 Microsoft Windows Information Disclosure Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

YoSmart YoLink Smart Hub

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to remotely control other users' smart home devices, intercept sensitive data, and hijack sessions. The following versions of YoSmart YoLink Smart Hub are affected: YoSmart server (CVE-2025-59449, CVE-2025-59451) YoLink Smart Hub (CVE-2025-59452) YoLink Mobile Appication (CVE-2025-59448) CVSS Vendor Equipment Vulnerabilities…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to remotely control other users' smart home devices, intercept sensitive data, and hijack sessions. The following versions of YoSmart YoLink Smart Hub are affected: YoSmart server (CVE-2025-59449, CVE-2025-59451) YoLink Smart Hub (CVE-2025-59452) YoLink Mobile Appication (CVE-2025-59448) CVSS Vendor Equipment Vulnerabilities v3 5.8 YoSmart YoSmart YoLink Smart Hub Incorrect Authorization, Generation of Predictable Numbers or Identifiers, Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors: Communications Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2025-59449 The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-account attacks, allowing an attacker to remotely operate affected devices if the attacker obtains the associated device IDs. Because YoLink device IDs are predictable, an attacker can exploit this to gain full control over any other YoLink user's devices. View CVE Details Affected Products YoSmart YoLink Smart Hub Vendor: YoSmart Product Version: YoSmart server: vers:all/* Product Status: known_affected Remediations Mitigation YoSmart recommends that users take the following actions to mitigate these vulnerabilities: Mitigation CVE-2025-59449 & CVE-2025-59451 - YoSmart's engineering team resolved these vulnerabilities on the server backend. No user actions are required Mitigation For more information visit the YoSmart Security Advisory. Relevant CWE: CWE-863 Incorrect Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.9 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N CVE-2025-59452 The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50. View CVE Details Affected Products YoSmart YoLink Smart Hub Vendor: YoSmart Product Version: YoSmart YoLink Smart Hub: 0382 Product Status: known_affected Remediations Mitigation YoSmart recommends that users take the following actions to mitigate these vulnerabilities: Mitigation CVE-2025-59452 - YoSmart released update 0383 to support a new, dynamic authentication algorithm. This will be released as an automatic over-the-air update and no user action is required. Mitigation For more information visit the YoSmart Security Advisory. Relevant CWE: CWE-340 Generation of Predictable Numbers or Identifiers Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.8 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N CVE-2025-59448 Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with the traffic to control affected devices. This affects YoLink Mobile Application 1.40.41 and YoLink MQTT Broker. View CVE Details Affected Products YoSmart YoLink Smart Hub Vendor: YoSmart Product Version: YoSmart YoLink Mobile Appication: <v1.40.45 Product Status: known_affected Remediations Mitigation YoSmart recommends that users take the following actions to mitigate these vulnerabilities: Mitigation CVE-2025-59448 - YoSmart recommends that users update to version 1.40.45 or later to mitigate this vulnerability. Mitigation For more information visit the YoSmart Security Advisory. Relevant CWE: CWE-319 Cleartext Transmission of Sensitive Information Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.7 MEDIUM CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N CVE-2025-59451 The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes. View CVE Details Affected Products YoSmart YoLink Smart Hub Vendor: YoSmart Product Version: YoSmart server: vers:all/* Product Status: known_affected Remediations Mitigation YoSmart recommends that users take the following actions to mitigate these vulnerabilities: Mitigation CVE-2025-59449 & CVE-2025-59451 - YoSmart's engineering team resolved these vulnerabilities on the server backend. No user actions are required Mitigation For more information visit the YoSmart Security Advisory. Relevant CWE: CWE-863 Incorrect Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 3.5 LOW CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N Acknowledgments Nick Cerne of Bishop Fox reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-13 Date Revision Summary 2026-01-13 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-8110 Gogs Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-8110 Gogs Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

Hitachi Energy Asset Suite

View CSAF Summary Hitachi Energy is aware of a Jasper Report vulnerability that affects the Asset Suite product versions mentioned in this document below. This vulnerability can be exploited to carry out remote code execution (RCE) attack on the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy Asset Suite are…
Read full source summary
View CSAF Summary Hitachi Energy is aware of a Jasper Report vulnerability that affects the Asset Suite product versions mentioned in this document below. This vulnerability can be exploited to carry out remote code execution (RCE) attack on the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy Asset Suite are affected: Asset Suite (CVE-2025-10492) CVSS Vendor Equipment Vulnerabilities v3 9.8 Hitachi Energy Hitachi Energy Asset Suite Deserialization of Untrusted Data Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-10492 A vulnerability exists in Jasper Report third party component of Asset Suite. A Java deserialization vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library. View CVE Details Affected Products Hitachi Energy Asset Suite Vendor: Hitachi Energy Product Version: Asset Suite versions 9.7 and prior Product Status: known_affected Remediations Vendor fix Update to version 9.8 Mitigation Restrict the loading of external custom reports created by end users by allowing only trusted Jasper reports generated by the system administrator Mitigation Apply general mitigation factors Relevant CWE: CWE-502 Deserialization of Untrusted Data Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgments Hitachi Energy PSIRT reported this vulnerability to CISA. Notice The information in this document is subject to change without notice and should not be construed as a commitment by Hitachi Energy. Hitachi Energy provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall Hitachi Energy or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if Hitachi Energy or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from Hitachi Energy and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners. Support For additional information and support please contact your product provider or Hitachi Energy service organization. For contact information, see https://www.hitachienergy.com/contact-us/ for Hitachi Energy contact-centers. General Mitigation Factors Recommended security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network. Such practices include that process control systems are physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed, and others that have to be evaluated case by case. Process control systems should not be used for Internet surfing, instant messaging, or receiving e-mails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system. Proper password policies and processes should be followed. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Hitachi Energy PSIRT 8DBD000231 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Hitachi Energy PSIRT directly for any questions regarding this advisory. Revision History Initial Release Date: 2025-12-09 Date Revision Summary 2025-12-09 1 Initial public release 2026-01-08 2 Initial Republication of Hitachi Energy PSIRT 8DBD000231 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2009-0556 Microsoft Office PowerPoint Code Injection Vulnerability CVE-2025-37164 HPE OneView Code Injection Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding…
Read full source summary
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2009-0556 Microsoft Office PowerPoint Code Injection Vulnerability CVE-2025-37164 HPE OneView Code Injection Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

Columbia Weather Systems MicroServer

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to redirect connections to an attacker controlled device, gain admin access to the web portal, or gain limited shell access. The following versions of Columbia Weather Systems MicroServer are affected: MicroServer firmware (CVE-2025-61939, CVE-2025-64305, CVE-2025-66620) CVSS Vendor Equipment Vulnerabilities v3 8.8 Columbia…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to redirect connections to an attacker controlled device, gain admin access to the web portal, or gain limited shell access. The following versions of Columbia Weather Systems MicroServer are affected: MicroServer firmware (CVE-2025-61939, CVE-2025-64305, CVE-2025-66620) CVSS Vendor Equipment Vulnerabilities v3 8.8 Columbia Weather Systems Columbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended Endpoints, Cleartext Storage in a File or on Disk, Command Shell in Externally Accessible Directory Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: United States Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2025-61939 An unused function in the MicroServer can start a reverse ssh connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS responses, can redirect the SSH connection to an attacker controlled device. View CVE Details Affected Products Columbia Weather Systems MicroServer Vendor: Columbia Weather Systems Product Version: Columbia Weather Systems MicroServer firmware: <MS_4.1_14142 Product Status: known_affected Remediations Vendor fix Columbia Weather Systems recommends users update the MicroServer firmware to version MS_4.1_14142 or later. To obtain the update, users should contact Columbia Weather Systems Support directly via email (support@columbiaweather.com) or phone (503-629-0887) for assistance. Relevant CWE: CWE-923 Improper Restriction of Communication Channel to Intended Endpoints Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2025-64305 The MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal. View CVE Details Affected Products Columbia Weather Systems MicroServer Vendor: Columbia Weather Systems Product Version: Columbia Weather Systems MicroServer firmware: <MS_4.1_14142 Product Status: known_affected Remediations Vendor fix Columbia Weather Systems recommends users update the MicroServer firmware to version MS_4.1_14142 or later. To obtain the update, users should contact Columbia Weather Systems Support directly via email (support@columbiaweather.com) or phone (503-629-0887) for assistance. Relevant CWE: CWE-313 Cleartext Storage in a File or on Disk Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2025-66620 An unused webshell in the MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An attacker with admin access to the MicroServer can gain limited shell access, enabling persistence through reverse shells, and the ability to modify or remove data stored in the file system. View CVE Details Affected Products Columbia Weather Systems MicroServer Vendor: Columbia Weather Systems Product Version: Columbia Weather Systems MicroServer firmware: <MS_4.1_14142 Product Status: known_affected Remediations Vendor fix Columbia Weather Systems recommends users update the MicroServer firmware to version MS_4.1_14142 or later. To obtain the update, users should contact Columbia Weather Systems Support directly via email (support@columbiaweather.com) or phone (503-629-0887) for assistance. Relevant CWE: CWE-553 Command Shell in Externally Accessible Directory Metrics CVSS Version Base Score Base Severity Vector String 3.1 8 HIGH CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Acknowledgments UsrPacific/Columbia Weather Systems reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2025-01-06 Date Revision Summary 2026-01-06 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Releases Two Industrial Control Systems Advisories

CISA released two Industrial Control Systems (ICS) Advisories. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-364-01: WHILL C2 Wheelchairs ICSA-25-345-03: AzeoTech DAQFactory (Update A) CISA encourages users and administrators to review newly released ICS Advisories for technical details and mitigations.
· CISA Cybersecurity Advisory

WHILL Model C2 Electric Wheelchairs and Model F Power Chairs

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to take control over the product. The following versions of WHILL Model C2 Electric Wheelchairs and Model F Power Chairs are affected: Model C2 Electric WheelChair (CVE-2025-14346) Model F Power Chair (CVE-2025-14346) CVSS Vendor Equipment Vulnerabilities v3 9.8 WHILL Inc. WHILL Model C2 Electric…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to take control over the product. The following versions of WHILL Model C2 Electric Wheelchairs and Model F Power Chairs are affected: Model C2 Electric WheelChair (CVE-2025-14346) Model F Power Chair (CVE-2025-14346) CVSS Vendor Equipment Vulnerabilities v3 9.8 WHILL Inc. WHILL Model C2 Electric Wheelchairs and Model F Power Chairs Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: Japan Vulnerabilities Expand All + CVE-2025-14346 WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulate configuration profiles without any credentials or user interaction. View CVE Details Affected Products WHILL Model C2 Electric Wheelchairs and Model F Power Chairs Vendor: WHILL Inc. Product Version: WHILL Inc. Model C2 Electric WheelChair: vers:all/*, WHILL Inc. Model F Power Chair: vers:all/* Product Status: known_affected Remediations Mitigation WHILL has deployed the following fixes on December 29th, 2025: Mitigation Device-Side Speed Profile Protection: Mitigation Implemented a safeguard in the wheelchair firmware to prevent unauthorized modification of speed profiles from the mobile application. Mitigation Unlock Command Restriction During Motion: Mitigation Block unlock commands issued from either the mobile app or the smart key while the wheelchair is in motion. Mitigation Application JSON File Obfuscation: Mitigation Obfuscate the configuration files used by the mobile application by converting JSON files into a binary format on both Android and iOS platforms. Mitigation For more information, contact WHILL Inc. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgments Billy Rios, Jesse Young, Brandon Rothel, Jonathan Butts, Henri Hein, Justin Boling, Nick Kulesza, Ken Natividad, and Carl Schuettthe of the Exploit Development Team - QED Secure Solutions reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. For more information, contact WHILL Inc. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2025-12-30 Date Revision Summary 2025-12-30 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-14847 MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD)…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-14847 MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

CISA Releases One Industrial Control Systems Advisory

CISA released one Industrial Control Systems (ICS) Advisory. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-177-01 Mitsubishi Electric Air Conditioning Systems (Update B) CISA encourages users and administrators to review the newly released ICS advisory for technical details and mitigations.
· CISA Cybersecurity Advisory

NIST and CISA Release Draft Interagency Report on Protecting Tokens and Assertions from Tampering Theft and Misuse for Public Comment

The Cybersecurity and Infrastructure Security Agency (CISA) and National Institute of Standards and Technology (NIST) have released an initial draft of Interagency Report (IR) 8597 Protecting Tokens and Assertions from Forgery, Theft, and Misuse for public comment through January 30, 2026. This report is in response to Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order…
Read full source summary
The Cybersecurity and Infrastructure Security Agency (CISA) and National Institute of Standards and Technology (NIST) have released an initial draft of Interagency Report (IR) 8597 Protecting Tokens and Assertions from Forgery, Theft, and Misuse for public comment through January 30, 2026. This report is in response to Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144, providing implementation guidance to help federal agencies and cloud service providers (CSPs) protect identity tokens and assertions from forgery, theft, and misuse. Recent cybersecurity incidents at major cloud service providers have focused on stealing, modifying, or forging identity tokens and assertions to gain access to protected resources. This report covers the controls for identity access management (IAM) systems that rely on digitally signed assertions and tokens when making access decisions. It discusses how CSPs and cloud consumers, including government agencies, can better define their respective roles and responsibilities for managing IAM controls in cloud environments. It establishes principles for both CSPs and cloud consumers, calling on CSPs to apply Secure by Design best practices, and to prioritize transparency, configurability, and interoperability, empowering consumers to better defend their diverse environments. It also calls upon federal agencies to understand the architecture and deployment models of their procured CSPs to ensure proper alignment with risk posture and threat environment. Comments on the report may be submitted to iam@list.nist.gov. Please visit NIST’s site for more information.
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-52163 Digiever DS-2105 Pro Missing Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-52163 Digiever DS-2105 Pro Missing Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

CISA and Partners Release Update to Malware Analysis Report BRICKSTORM Backdoor

Today, the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency, and Canadian Centre for Cyber Security released an update to the Malware Analysis Report BRICKSTORM Backdoor with indicators of compromise (IOCs) and detection signatures for additional BRICKSTORM samples. This update provides information on additional samples, including Rust-based samples. These samples demonstrate…
Read full source summary
Today, the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency, and Canadian Centre for Cyber Security released an update to the Malware Analysis Report BRICKSTORM Backdoor with indicators of compromise (IOCs) and detection signatures for additional BRICKSTORM samples. This update provides information on additional samples, including Rust-based samples. These samples demonstrate advanced persistence and defense evasion mechanisms, such as running as background services, and enhanced command and control capabilities through encrypted WebSocket connections. The update includes two new detection signatures in the form of YARA rules, enabling organizations to better identify BRICKSTORM-related activity. Organizations are strongly encouraged to deploy these updated IOCs and signatures, and to follow the detection guidance to scan for and respond to BRICKSTORM infections If BRICKSTORM, similar malware, or potentially related activity is detected, report the incident to CISA’s 24/7 Operations Center at contact@cisa.dhs.gov or (888) 282-0870.
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-14733 WatchGuard Firebox Out-of-Bounds Write Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-14733 WatchGuard Firebox Out-of-Bounds Write Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

Siemens Interniche IP-Stack

View CSAF Summary Multiple Industrial products are affected by a vulnerability in the Interniche IP-Stack. The affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an…
Read full source summary
View CSAF Summary Multiple Industrial products are affected by a vulnerability in the Interniche IP-Stack. The affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an attacker can inject IP packets with spoofed addresses at precisely timed moments, and it affects only TCP-based services. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens Interniche IP-Stack are affected: SIDOOR ATD430W (CVE-2025-40820) SIDOOR ATE530G COATED (6FB1221-5SM10-7BP0) (CVE-2025-40820) SIDOOR ATE530S COATED (CVE-2025-40820) SIMATIC CFU DIQ (6ES7655-5PX31-1XX0) (CVE-2025-40820) SIMATIC CFU PA (6ES7655-5PX11-0XX0) (CVE-2025-40820) SIMATIC CFU PA (6ES7655-5PX11-1XX0) (CVE-2025-40820) SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (CVE-2025-40820) SIMATIC ET 200clean, CM 8x IO-Link (6ES7148-7JH00-0BB0) (CVE-2025-40820) SIMATIC ET 200clean, DI 16x24VDC (6ES7141-7BH00-0BB0) (CVE-2025-40820) SIMATIC ET 200clean, DIQ 16x24VDC/0,5A (6ES7143-7BH00-0BB0) (CVE-2025-40820) SIMATIC ET 200eco PN, AI 8xRTD/TC, M12-L (6ES7144-6JF00-0BB0) (CVE-2025-40820) SIMATIC ET 200eco PN, CM 4x IO-Link, M12-L (6ES7148-6JE00-0BB0) (CVE-2025-40820) SIMATIC ET 200eco PN, CM 8x IO-Link, M12-L (6ES7148-6JG00-0BB0) (CVE-2025-40820) SIMATIC ET 200eco PN, CM 8x IO-Link, M12-L (6ES7148-6JJ00-0BB0) (CVE-2025-40820) SIMATIC ET 200eco PN, DI 16x24VDC, M12-L (6ES7141-6BH00-0BB0) (CVE-2025-40820) SIMATIC ET 200eco PN, DI 8x24VDC, M12-L (6ES7141-6BG00-0BB0) (CVE-2025-40820) SIMATIC ET 200eco PN, DIQ 16x24VDC/2A, M12-L (6ES7143-6BH00-0BB0) (CVE-2025-40820) SIMATIC ET 200eco PN, DQ 8x24VDC/0,5A, M12-L (6ES7142-6BG00-0BB0) (CVE-2025-40820) SIMATIC ET 200eco PN, DQ 8x24VDC/2A, M12-L (6ES7142-6BR00-0BB0) (CVE-2025-40820) SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0) (CVE-2025-40820) SIMATIC ET 200pro IM 154-8 PN/DP CPU (6ES7154-8AB01-0AB0) (CVE-2025-40820) SIMATIC ET 200pro IM 154-8F PN/DP CPU (6ES7154-8FB01-0AB0) (CVE-2025-40820) SIMATIC ET 200pro IM 154-8FX PN/DP CPU (6ES7154-8FX00-0AB0) (CVE-2025-40820) SIMATIC ET 200S IM 151-8 PN/DP CPU (6ES7151-8AB01-0AB0) (CVE-2025-40820) SIMATIC ET 200S IM 151-8F PN/DP CPU (6ES7151-8FB01-0AB0) (CVE-2025-40820) SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ00-0AB0) (CVE-2025-40820) SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DJ00-0AB0) (CVE-2025-40820) SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SK00-0AB0) (CVE-2025-40820) SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DK00-0AB0) (CVE-2025-40820) SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0) (CVE-2025-40820) SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants) (CVE-2025-40820) SIMATIC ET 200SP IM 155-6 PN HF (6ES7155-6AU00-0CN0) (CVE-2025-40820) SIMATIC ET 200SP IM 155-6 PN/2 HF (6ES7155-6AU01-0CN0) (CVE-2025-40820) SIMATIC ET 200SP IM 155-6 PN/3 HF (6ES7155-6AU30-0CN0) (CVE-2025-40820) SIMATIC PN/MF Coupler (6ES7158-3MU10-0XA0) (CVE-2025-40820) SIMATIC PN/PN Coupler (6ES7158-3AD10-0XA0) (CVE-2025-40820) SIMATIC Power Line Booster PLB, Base Module (6ES7972-5AA10-0AB0) (CVE-2025-40820) SIMATIC Power Line Booster PLB, Modem Module ST (6ES7972-5AA51-0AB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1211C DC/DC/Rly (6ES7211-1HE40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1212C AC/DC/Rly (6ES7212-1BE40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1212C DC/DC/DC (6ES7212-1AE40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1212C DC/DC/Rly (6ES7212-1HE40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1212FC DC/DC/DC (6ES7212-1AF40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1212FC DC/DC/Rly (6ES7212-1HF40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1214C AC/DC/Rly (6ES7214-1BG40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1214C DC/DC/DC (6ES7214-1AG40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1214C DC/DC/Rly (6ES7214-1HG40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1214FC DC/DC/DC (6ES7214-1AF40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1214FC DC/DC/Rly (6ES7214-1HF40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1215C AC/DC/Rly (6ES7215-1BG40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1215C DC/DC/DC (6ES7215-1AG40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1215C DC/DC/Rly (6ES7215-1HG40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1215FC DC/DC/DC (6ES7215-1AF40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1215FC DC/DC/Rly (6ES7215-1HF40-0XB0) (CVE-2025-40820) SIMATIC S7-1200 CPU 1217C DC/DC/DC (6ES7217-1AG40-0XB0) (CVE-2025-40820) SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK00-0AB0) (CVE-2025-40820) SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK00-0AB0) (CVE-2025-40820) SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL00-0AB0) (CVE-2025-40820) SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL00-0AB0) (CVE-2025-40820) SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM00-0AB0) (CVE-2025-40820) SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM00-0AB0) (CVE-2025-40820) SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN00-0AB0) (CVE-2025-40820) SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN00-0AB0) (CVE-2025-40820) SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (CVE-2025-40820) SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0) (CVE-2025-40820) SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA0) (CVE-2025-40820) SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA1) (CVE-2025-40820) SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA0) (CVE-2025-40820) SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA1) (CVE-2025-40820) SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA0) (CVE-2025-40820) SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA1) (CVE-2025-40820) SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA0) (CVE-2025-40820) SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA1) (CVE-2025-40820) SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA0) (CVE-2025-40820) SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA1) (CVE-2025-40820) SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA0) (CVE-2025-40820) SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA1) (CVE-2025-40820) SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA0) (CVE-2025-40820) SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA1) (CVE-2025-40820) SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA0) (CVE-2025-40820) SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA1) (CVE-2025-40820) SIMATIC S7-300 CPU 314C-2 PN/DP (6ES7314-6EH04-0AB0) (CVE-2025-40820) SIMATIC S7-300 CPU 315-2 PN/DP (6ES7315-2EH14-0AB0) (CVE-2025-40820) SIMATIC S7-300 CPU 315F-2 PN/DP (6ES7315-2FJ14-0AB0) (CVE-2025-40820) SIMATIC S7-300 CPU 315T-3 PN/DP (6ES7315-7TJ10-0AB0) (CVE-2025-40820) SIMATIC S7-300 CPU 317-2 PN/DP (6ES7317-2EK14-0AB0) (CVE-2025-40820) SIMATIC S7-300 CPU 317F-2 PN/DP (6ES7317-2FK14-0AB0) (CVE-2025-40820) SIMATIC S7-300 CPU 317T-3 PN/DP (6ES7317-7TK10-0AB0) (CVE-2025-40820) SIMATIC S7-300 CPU 317TF-3 PN/DP (6ES7317-7UL10-0AB0) (CVE-2025-40820) SIMATIC S7-300 CPU 319-3 PN/DP (6ES7318-3EL01-0AB0) (CVE-2025-40820) SIMATIC S7-300 CPU 319F-3 PN/DP (6ES7318-3FL01-0AB0) (CVE-2025-40820) SIMATIC S7-400 CPU 412-2 PN V7 (6ES7412-2EK07-0AB0) (CVE-2025-40820) SIMATIC S7-400 CPU 414-3 PN/DP V7 (6ES7414-3EM07-0AB0) (CVE-2025-40820) SIMATIC S7-400 CPU 414F-3 PN/DP V7 (6ES7414-3FM07-0AB0) (CVE-2025-40820) SIMATIC S7-400 CPU 416-3 PN/DP V7 (6ES7416-3ES07-0AB0) (CVE-2025-40820) SIMATIC S7-400 CPU 416F-3 PN/DP V7 (6ES7416-3FS07-0AB0) (CVE-2025-40820) SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants) (CVE-2025-40820) SIMATIC S7-410 V10 CPU family (incl. SIPLUS variants) (CVE-2025-40820) SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants) (CVE-2025-40820) SIMATIC TDC CP51M1 (CVE-2025-40820) SIMATIC TDC CPU555 (CVE-2025-40820) SIMOCODE pro V Ethernet/IP (incl. SIPLUS variants) (CVE-2025-40820) SIMOCODE pro V PROFINET (CVE-2025-40820) SINUMERIK 840D sl (CVE-2025-40820) SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-2AC0) (CVE-2025-40820) SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-7AC0) (CVE-2025-40820) SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL (6AG2155-5AA00-1AC0) (CVE-2025-40820) SIPLUS ET 200S IM 151-8 PN/DP CPU (6AG1151-8AB01-7AB0) (CVE-2025-40820) SIPLUS ET 200S IM 151-8F PN/DP CPU (6AG1151-8FB01-2AB0) (CVE-2025-40820) SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK00-2AB0) (CVE-2025-40820) SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU00-2CN0) (CVE-2025-40820) SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU00-4CN0) (CVE-2025-40820) SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-2CN0) (CVE-2025-40820) SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-7CN0) (CVE-2025-40820) SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL (6AG2155-6AU00-1CN0) (CVE-2025-40820) SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL (6AG2155-6AU01-1CN0) (CVE-2025-40820) SIPLUS ET 200SP IM 155-6 PN HF TX RAIL (6AG2155-6AU01-4CN0) (CVE-2025-40820) SIPLUS HCS4200 CIM4210 (6BK1942-1AA00-0AA0) (CVE-2025-40820) SIPLUS HCS4200 CIM4210C (6BK1942-1AA00-0AA1) (CVE-2025-40820) SIPLUS HCS4300 CIM4310 (6BK1943-1AA00-0AA0) (CVE-2025-40820) SIPLUS NET PN/PN Coupler (6AG2158-3AD10-4XA0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1212 AC/DC/RLY (6AG1212-1BE40-4XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1212 DC/DC/RLY (6AG1212-1HE40-2XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1212 DC/DC/RLY (6AG1212-1HE40-4XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1212C AC/DC/RLY (6AG1212-1BE40-2XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1212C DC/DC/DC (6AG1212-1AE40-2XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1212C DC/DC/DC (6AG1212-1AE40-4XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1212C DC/DC/DC RAIL (6AG2212-1AE40-1XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1214 AC/DC/RLY (6AG1214-1BG40-5XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1214 DC/DC/RLY (6AG1214-1HG40-2XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1214C AC/DC/RLY (6AG1214-1BG40-2XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1214C AC/DC/RLY (6AG1214-1BG40-4XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1214C DC/DC/DC (6AG1214-1AG40-2XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1214C DC/DC/DC (6AG1214-1AG40-4XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1214C DC/DC/DC (6AG1214-1AG40-5XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1214C DC/DC/DC RAIL (6AG2214-1AG40-1XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1214C DC/DC/RLY (6AG1214-1HG40-4XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1214C DC/DC/RLY (6AG1214-1HG40-5XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1214FC DC/DC/DC (6AG1214-1AF40-5XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1214FC DC/DC/RLY (6AG1214-1HF40-5XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-4XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-5XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1215 DC/DC/DC (6AG1215-1AG40-2XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1215 DC/DC/DC (6AG1215-1AG40-4XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-2XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-4XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-5XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1215C AC/DC/RLY (6AG1215-1BG40-2XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1215C DC/DC/DC (6AG1215-1AG40-5XB0) (CVE-2025-40820) SIPLUS S7-1200 CPU 1215FC DC/DC/DC (6AG1215-1AF40-5XB0) (CVE-2025-40820) SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK00-2AB0) (CVE-2025-40820) SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK00-2AB0) (CVE-2025-40820) SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL00-2AB0) (CVE-2025-40820) SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL00-2AB0) (CVE-2025-40820) SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN00-2AB0) (CVE-2025-40820) SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN00-7AB0) (CVE-2025-40820) SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN00-2AB0) (CVE-2025-40820) SIPLUS S7-300 CPU 314C-2 PN/DP (6AG1314-6EH04-7AB0) (CVE-2025-40820) SIPLUS S7-300 CPU 315-2 PN/DP (6AG1315-2EH14-7AB0) (CVE-2025-40820) SIPLUS S7-300 CPU 315F-2 PN/DP (6AG1315-2FJ14-2AB0) (CVE-2025-40820) SIPLUS S7-300 CPU 317-2 PN/DP (6AG1317-2EK14-7AB0) (CVE-2025-40820) SIPLUS S7-300 CPU 317F-2 PN/DP (6AG1317-2FK14-2AB0) (CVE-2025-40820) SIPLUS S7-400 CPU 414-3 PN/DP V7 (6AG1414-3EM07-7AB0) (CVE-2025-40820) SIPLUS S7-400 CPU 416-3 PN/DP V7 (6AG1416-3ES07-7AB0) (CVE-2025-40820) SIWAREX WP231 (7MH4960-2AA01) (CVE-2025-40820) SIWAREX WP241 (7MH4960-4AA01) (CVE-2025-40820) SIWAREX WP251 (7MH4960-6AA01) (CVE-2025-40820) SIWAREX WP521 ST (7MH4980-1AA01) (CVE-2025-40820) SIWAREX WP522 ST (7MH4980-2AA01) (CVE-2025-40820) CVSS Vendor Equipment Vulnerabilities v3 7.5 Siemens Siemens Interniche IP-Stack Improper Verification of Source of a Communication Channel Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2025-40820 Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an attacker can inject IP packets with spoofed addresses at precisely timed moments, and it affects only TCP-based services. View CVE Details Affected Products Siemens Interniche IP-Stack Vendor: Siemens Product Version: SIDOOR ATD430W, SIDOOR ATE530G COATED (6FB1221-5SM10-7BP0), SIDOOR ATE530S COATED, SIMATIC CFU DIQ (6ES7655-5PX31-1XX0), SIMATIC CFU PA (6ES7655-5PX11-0XX0), SIMATIC CFU PA (6ES7655-5PX11-1XX0), SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0), SIMATIC ET 200clean, CM 8x IO-Link (6ES7148-7JH00-0BB0), SIMATIC ET 200clean, DI 16x24VDC (6ES7141-7BH00-0BB0), SIMATIC ET 200clean, DIQ 16x24VDC/0,5A (6ES7143-7BH00-0BB0), SIMATIC ET 200eco PN, AI 8xRTD/TC, M12-L (6ES7144-6JF00-0BB0), SIMATIC ET 200eco PN, CM 4x IO-Link, M12-L (6ES7148-6JE00-0BB0), SIMATIC ET 200eco PN, CM 8x IO-Link, M12-L (6ES7148-6JG00-0BB0), SIMATIC ET 200eco PN, CM 8x IO-Link, M12-L (6ES7148-6JJ00-0BB0), SIMATIC ET 200eco PN, DI 16x24VDC, M12-L (6ES7141-6BH00-0BB0), SIMATIC ET 200eco PN, DI 8x24VDC, M12-L (6ES7141-6BG00-0BB0), SIMATIC ET 200eco PN, DIQ 16x24VDC/2A, M12-L (6ES7143-6BH00-0BB0), SIMATIC ET 200eco PN, DQ 8x24VDC/0,5A, M12-L (6ES7142-6BG00-0BB0), SIMATIC ET 200eco PN, DQ 8x24VDC/2A, M12-L (6ES7142-6BR00-0BB0), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0), SIMATIC ET 200pro IM 154-8 PN/DP CPU (6ES7154-8AB01-0AB0), SIMATIC ET 200pro IM 154-8F PN/DP CPU (6ES7154-8FB01-0AB0), SIMATIC ET 200pro IM 154-8FX PN/DP CPU (6ES7154-8FX00-0AB0), SIMATIC ET 200S IM 151-8 PN/DP CPU (6ES7151-8AB01-0AB0), SIMATIC ET 200S IM 151-8F PN/DP CPU (6ES7151-8FB01-0AB0), SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ00-0AB0), SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DJ00-0AB0), SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SK00-0AB0), SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DK00-0AB0), SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0), SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants), SIMATIC ET 200SP IM 155-6 PN HF (6ES7155-6AU00-0CN0), SIMATIC ET 200SP IM 155-6 PN/2 HF (6ES7155-6AU01-0CN0), SIMATIC ET 200SP IM 155-6 PN/3 HF (6ES7155-6AU30-0CN0), SIMATIC PN/MF Coupler (6ES7158-3MU10-0XA0), SIMATIC PN/PN Coupler (6ES7158-3AD10-0XA0), SIMATIC Power Line Booster PLB, Base Module (6ES7972-5AA10-0AB0), SIMATIC Power Line Booster PLB, Modem Module ST (6ES7972-5AA51-0AB0), SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0), SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0), SIMATIC S7-1200 CPU 1211C DC/DC/Rly (6ES7211-1HE40-0XB0), SIMATIC S7-1200 CPU 1212C AC/DC/Rly (6ES7212-1BE40-0XB0), SIMATIC S7-1200 CPU 1212C DC/DC/DC (6ES7212-1AE40-0XB0), SIMATIC S7-1200 CPU 1212C DC/DC/Rly (6ES7212-1HE40-0XB0), SIMATIC S7-1200 CPU 1212FC DC/DC/DC (6ES7212-1AF40-0XB0), SIMATIC S7-1200 CPU 1212FC DC/DC/Rly (6ES7212-1HF40-0XB0), SIMATIC S7-1200 CPU 1214C AC/DC/Rly (6ES7214-1BG40-0XB0), SIMATIC S7-1200 CPU 1214C DC/DC/DC (6ES7214-1AG40-0XB0), SIMATIC S7-1200 CPU 1214C DC/DC/Rly (6ES7214-1HG40-0XB0), SIMATIC S7-1200 CPU 1214FC DC/DC/DC (6ES7214-1AF40-0XB0), SIMATIC S7-1200 CPU 1214FC DC/DC/Rly (6ES7214-1HF40-0XB0), SIMATIC S7-1200 CPU 1215C AC/DC/Rly (6ES7215-1BG40-0XB0), SIMATIC S7-1200 CPU 1215C DC/DC/DC (6ES7215-1AG40-0XB0), SIMATIC S7-1200 CPU 1215C DC/DC/Rly (6ES7215-1HG40-0XB0), SIMATIC S7-1200 CPU 1215FC DC/DC/DC (6ES7215-1AF40-0XB0), SIMATIC S7-1200 CPU 1215FC DC/DC/Rly (6ES7215-1HF40-0XB0), SIMATIC S7-1200 CPU 1217C DC/DC/DC (6ES7217-1AG40-0XB0), SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK00-0AB0), SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK00-0AB0), SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL00-0AB0), SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL00-0AB0), SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM00-0AB0), SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM00-0AB0), SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN00-0AB0), SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN00-0AB0), SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0), SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0), SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA0), SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA1), SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA0), SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA1), SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA0), SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA1), SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA0), SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA1), SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA0), SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA1), SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA0), SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA1), SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA0), SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA1), SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA0), SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA1), SIMATIC S7-300 CPU 314C-2 PN/DP (6ES7314-6EH04-0AB0), SIMATIC S7-300 CPU 315-2 PN/DP (6ES7315-2EH14-0AB0), SIMATIC S7-300 CPU 315F-2 PN/DP (6ES7315-2FJ14-0AB0), SIMATIC S7-300 CPU 315T-3 PN/DP (6ES7315-7TJ10-0AB0), SIMATIC S7-300 CPU 317-2 PN/DP (6ES7317-2EK14-0AB0), SIMATIC S7-300 CPU 317F-2 PN/DP (6ES7317-2FK14-0AB0), SIMATIC S7-300 CPU 317T-3 PN/DP (6ES7317-7TK10-0AB0), SIMATIC S7-300 CPU 317TF-3 PN/DP (6ES7317-7UL10-0AB0), SIMATIC S7-300 CPU 319-3 PN/DP (6ES7318-3EL01-0AB0), SIMATIC S7-300 CPU 319F-3 PN/DP (6ES7318-3FL01-0AB0), SIMATIC S7-400 CPU 412-2 PN V7 (6ES7412-2EK07-0AB0), SIMATIC S7-400 CPU 414-3 PN/DP V7 (6ES7414-3EM07-0AB0), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (6ES7414-3FM07-0AB0), SIMATIC S7-400 CPU 416-3 PN/DP V7 (6ES7416-3ES07-0AB0), SIMATIC S7-400 CPU 416F-3 PN/DP V7 (6ES7416-3FS07-0AB0), SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants), SIMATIC S7-410 V10 CPU family (incl. SIPLUS variants), SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants), SIMATIC TDC CP51M1, SIMATIC TDC CPU555, SIMOCODE pro V Ethernet/IP (incl. SIPLUS variants), SIMOCODE pro V PROFINET, SINUMERIK 840D sl, SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-2AC0), SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-7AC0), SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL (6AG2155-5AA00-1AC0), SIPLUS ET 200S IM 151-8 PN/DP CPU (6AG1151-8AB01-7AB0), SIPLUS ET 200S IM 151-8F PN/DP CPU (6AG1151-8FB01-2AB0), SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK00-2AB0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU00-2CN0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU00-4CN0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-2CN0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-7CN0), SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL (6AG2155-6AU00-1CN0), SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL (6AG2155-6AU01-1CN0), SIPLUS ET 200SP IM 155-6 PN HF TX RAIL (6AG2155-6AU01-4CN0), SIPLUS HCS4200 CIM4210 (6BK1942-1AA00-0AA0), SIPLUS HCS4200 CIM4210C (6BK1942-1AA00-0AA1), SIPLUS HCS4300 CIM4310 (6BK1943-1AA00-0AA0), SIPLUS NET PN/PN Coupler (6AG2158-3AD10-4XA0), SIPLUS S7-1200 CPU 1212 AC/DC/RLY (6AG1212-1BE40-4XB0), SIPLUS S7-1200 CPU 1212 DC/DC/RLY (6AG1212-1HE40-2XB0), SIPLUS S7-1200 CPU 1212 DC/DC/RLY (6AG1212-1HE40-4XB0), SIPLUS S7-1200 CPU 1212C AC/DC/RLY (6AG1212-1BE40-2XB0), SIPLUS S7-1200 CPU 1212C DC/DC/DC (6AG1212-1AE40-2XB0), SIPLUS S7-1200 CPU 1212C DC/DC/DC (6AG1212-1AE40-4XB0), SIPLUS S7-1200 CPU 1212C DC/DC/DC RAIL (6AG2212-1AE40-1XB0), SIPLUS S7-1200 CPU 1214 AC/DC/RLY (6AG1214-1BG40-5XB0), SIPLUS S7-1200 CPU 1214 DC/DC/RLY (6AG1214-1HG40-2XB0), SIPLUS S7-1200 CPU 1214C AC/DC/RLY (6AG1214-1BG40-2XB0), SIPLUS S7-1200 CPU 1214C AC/DC/RLY (6AG1214-1BG40-4XB0), SIPLUS S7-1200 CPU 1214C DC/DC/DC (6AG1214-1AG40-2XB0), SIPLUS S7-1200 CPU 1214C DC/DC/DC (6AG1214-1AG40-4XB0), SIPLUS S7-1200 CPU 1214C DC/DC/DC (6AG1214-1AG40-5XB0), SIPLUS S7-1200 CPU 1214C DC/DC/DC RAIL (6AG2214-1AG40-1XB0), SIPLUS S7-1200 CPU 1214C DC/DC/RLY (6AG1214-1HG40-4XB0), SIPLUS S7-1200 CPU 1214C DC/DC/RLY (6AG1214-1HG40-5XB0), SIPLUS S7-1200 CPU 1214FC DC/DC/DC (6AG1214-1AF40-5XB0), SIPLUS S7-1200 CPU 1214FC DC/DC/RLY (6AG1214-1HF40-5XB0), SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-4XB0), SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-5XB0), SIPLUS S7-1200 CPU 1215 DC/DC/DC (6AG1215-1AG40-2XB0), SIPLUS S7-1200 CPU 1215 DC/DC/DC (6AG1215-1AG40-4XB0), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-2XB0), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-4XB0), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-5XB0), SIPLUS S7-1200 CPU 1215C AC/DC/RLY (6AG1215-1BG40-2XB0), SIPLUS S7-1200 CPU 1215C DC/DC/DC (6AG1215-1AG40-5XB0), SIPLUS S7-1200 CPU 1215FC DC/DC/DC (6AG1215-1AF40-5XB0), SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK00-2AB0), SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK00-2AB0), SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL00-2AB0), SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL00-2AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN00-2AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN00-7AB0), SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN00-2AB0), SIPLUS S7-300 CPU 314C-2 PN/DP (6AG1314-6EH04-7AB0), SIPLUS S7-300 CPU 315-2 PN/DP (6AG1315-2EH14-7AB0), SIPLUS S7-300 CPU 315F-2 PN/DP (6AG1315-2FJ14-2AB0), SIPLUS S7-300 CPU 317-2 PN/DP (6AG1317-2EK14-7AB0), SIPLUS S7-300 CPU 317F-2 PN/DP (6AG1317-2FK14-2AB0), SIPLUS S7-400 CPU 414-3 PN/DP V7 (6AG1414-3EM07-7AB0), SIPLUS S7-400 CPU 416-3 PN/DP V7 (6AG1416-3ES07-7AB0), SIWAREX WP231 (7MH4960-2AA01), SIWAREX WP241 (7MH4960-4AA01), SIWAREX WP251 (7MH4960-6AA01), SIWAREX WP521 ST (7MH4980-1AA01), SIWAREX WP522 ST (7MH4980-2AA01) Product Status: known_affected Remediations Mitigation As a mitigation, disable the ethernet ports on the CPU and use a communication module (like CP) for communication instead No fix planned Currently no fix is planned None available Currently no fix is available Vendor fix Update to V1.3 or later version Vendor fix Update to V10.2 or later version Vendor fix Update to V2.0.0 or later version Vendor fix Update to V2.0.0 or later version Vendor fix Update to V4.4.0 or later version Vendor fix Update to V6.0.0 or later version Vendor fix Update to V8.3 or later version Workaround Limit TCP accessibility to trusted IP address Relevant CWE: CWE-940 Improper Verification of Source of a Communication Channel Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Acknowledgments Siemens ProductCERT reported this vulnerability to CISA. Qian Zou, Xuewei Feng, Ke Xu, Qi Li, Xueying Li, and Gang Jin of Zhongguancun Laboratory reported this vulnerability to Siemens Qian Zou, Xuewei Feng, Ke Xu, Qi Li, Xueying Li, and Gang Jin of Tsinghua University reported this vulnerability to Siemens General Recommendations As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity Additional Resources For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories Terms of Use The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Siemens ProductCERT SSA-915282 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2025-12-18 Date Revision Summary 2025-12-18 1 Initial Republication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Rockwell Automation Micro820, Micro850, Micro870

View CSAF Summary Successful exploitation of these vulnerabilities could result in a denial-of-service condition. The following versions of Rockwell Automation Micro820, Micro850, Micro870 are affected: Micro820 (CVE-2025-13823, CVE-2025-13824) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation Micro820, Micro850, Micro870 Dependency on Vulnerable Third-Party Component, Release of…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could result in a denial-of-service condition. The following versions of Rockwell Automation Micro820, Micro850, Micro870 are affected: Micro820 (CVE-2025-13823, CVE-2025-13824) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation Micro820, Micro850, Micro870 Dependency on Vulnerable Third-Party Component, Release of Invalid Pointer or Reference Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2025-13823 A security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers. This issue occurs when the controllers received multiple malformed packets during fuzzing, causing a recoverable fault. View CVE Details Affected Products Rockwell Automation Micro820, Micro850, Micro870 Vendor: Rockwell Automation Product Version: Rockwell Automation Micro820: <=V14.011 Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends users of Micro820 V14.011 and prior update to newer Micro820 controllers (L20E V23.011 or later). Mitigation Rockwell Automation recommends users of Micro850/870 update to V12.013 or later. The update can be downloaded from the Rockwell Automation website. Mitigation For CVE-2025-13823, Rockwell Automation advises users to disable IPv6 functionalities if they do not require the feature. Mitigation Rockwell Automation users using the affected software, who are not able to upgrade to one of the corrected versions, should follow Rockwell Automation's security best practices. Mitigation For more information, please review Rockwell Automation's advisory. Relevant CWE: CWE-1395 Dependency on Vulnerable Third-Party Component Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-13824 A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with a solid red Fault LED and becomes unresponsive. Upon power cycling, the controller will enter a recoverable fault. View CVE Details Affected Products Rockwell Automation Micro820, Micro850, Micro870 Vendor: Rockwell Automation Product Version: Rockwell Automation Micro820: <=V14.011 Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends users of Micro820 V14.011 and prior update to newer Micro820 controllers (L20E V23.011 or later). Mitigation Rockwell Automation recommends users of Micro850/870 update to V12.013 or later. The update can be downloaded from the Rockwell Automation website. Mitigation Rockwell Automation users using the affected software, who are not able to upgrade to one of the corrected versions, should follow Rockwell Automation's security best practices. Mitigation For more information, please review Rockwell Automation's advisory. Relevant CWE: CWE-763 Release of Invalid Pointer or Reference Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Acknowledgments Rockwell Automation reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2025-12-18 Date Revision Summary 2025-12-18 1 Initial Republication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Releases Nine Industrial Control Systems Advisories

CISA released nine Industrial Control Systems (ICS) Advisories. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-352-01 Inductive Automation Ignition ICSA-25-352-02 Schneider Electric EcoStruxure Foxboro DCS Advisor ICSA-25-352-03 National Instruments LabView ICSA-25-352-04 Mitsubishi Electric Iconics Digital Solutions and Mitsubishi…
Read full source summary
CISA released nine Industrial Control Systems (ICS) Advisories. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-352-01 Inductive Automation Ignition ICSA-25-352-02 Schneider Electric EcoStruxure Foxboro DCS Advisor ICSA-25-352-03 National Instruments LabView ICSA-25-352-04 Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electrics Products ICSA-25-352-05 Siemens Interniche IP-Stack ICSA-25-352-06 Advantech WebAccess/SCADA ICSA-25-352-07 Rockwell Automation Micro820, Micro850, Micro 870 ICSA-25-352-08 Axis Communications Camera Station Pro, Camera Station, and Device Manager ICSA-24-291-03 Mitsubishi Electric CNC Series (Update C) CISA encourages users and administrators to review newly released ICS Advisories for technical details and mitigations.
Browse saved snapshots