Multiple Critical Vulnerabilities Disclosed in Industrial Control Systems by CISA
CISA released thirteen advisories detailing critical vulnerabilities affecting a range of industrial control system (ICS) products from major vendors including Rockwell Automation, Siemens, Hitachi Energy, Schneider Electric, and Delta Electronics. The advisories highlight severe security flaws such as missing authentication for critical functions, improper authorization, buffer overflows, SQL injection, and improper certificate validation. For Siemens TeleControl Server Basic, a vulnerability (CVE-2025-40765) allows unauthenticated remote attackers to obtain password hashes and perform authenticated operations on the database service, with a CVSS v3.1 score of 9.8, indicating critical risk. Rockwell Automation's FactoryTalk View Machine Edition and PanelView Plus 7 are susceptible to path traversal and improper authorization, potentially granting attackers unauthorized access to device file systems and sensitive diagnostic information. FactoryTalk ViewPoint is vulnerable to XML external entity injection, which could result in denial-of-service conditions. Siemens SiPass Integrated faces multiple issues, including buffer overflows and cross-site scripting, which could enable arbitrary code execution and unauthorized access. The Siemens SIMATIC ET 200SP Communication Processors have a missing authentication flaw that could allow attackers to access configuration data remotely. Siemens SINEC NMS is affected by a SQL injection vulnerability that could let low-privileged users escalate privileges. Siemens Solid Edge products are exposed to out-of-bounds read and write vulnerabilities, risking application crashes or code execution. Siemens HyperLynx and Industrial Edge App Publisher are vulnerable to type confusion, potentially leading to arbitrary code execution via crafted HTML pages. Hitachi Energy MACH GWS products have incorrect default permissions and improper validation issues, which could allow attackers to tamper with system files, cause denial of service, or perform man-in-the-middle attacks. The advisories provide technical details, affected product versions, and recommended mitigations, urging administrators to review and apply patches or workarounds. The vulnerabilities impact critical infrastructure sectors such as manufacturing, energy, water, and transportation, with products deployed worldwide. Many of the flaws are remotely exploitable with low attack complexity, increasing the urgency for remediation. CISA emphasizes the importance of timely action to prevent exploitation, as several vulnerabilities could lead to unauthorized access, data manipulation, or disruption of essential services. The advisories also reference the need to consult vendor-specific security updates for the most current information. Organizations are advised to assess their exposure, prioritize patching, and implement recommended security controls to mitigate these risks. The coordinated disclosure underscores the ongoing threat to ICS environments and the necessity for robust security practices across operational technology networks.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
7 events from the most recent confirmed update back to the earliest known activity.
CISA discloses Siemens SINEC NMS SQL injection vulnerability
CISA advisory ICSA-25-289-08 disclosed CVE-2025-40755, an SQL injection flaw in Siemens SINEC NMS versions prior to V4.0 SP1 that could allow a low-privileged authenticated attacker to escalate privileges. Siemens recommended upgrading to V4.0 SP1 or later, and CISA reported no known public exploitation at publication.
Siemens discloses HyperLynx and Industrial Edge App Publisher flaw
CISA advisory ICSA-25-289-10 disclosed CVE-2025-6554, a type confusion vulnerability affecting Siemens HyperLynx and Industrial Edge App Publisher. Siemens released a patch for Industrial Edge App Publisher version 1.23.5 or later, while no fix was available for HyperLynx at the time of publication.
Siemens releases SiPass integrated V3.0 to fix four vulnerabilities
CISA advisory ICSA-25-289-06 disclosed four vulnerabilities in Siemens SiPass integrated versions prior to V3.0, including buffer overflow, stored XSS, broken access control, and recoverable password storage issues. Siemens said V3.0 or later addresses the flaws, and CISA noted no known public exploitation and that the issues were not remotely exploitable.
Rockwell patches FactoryTalk View ME and PanelView Plus 7 flaws
CISA advisory ICSA-25-289-01 detailed two vulnerabilities, CVE-2025-9064 and CVE-2025-9063, in Rockwell Automation FactoryTalk View Machine Edition and PanelView Plus 7. Rockwell released patches and mitigation guidance, and CISA said no public exploitation was known at publication.
CISA issues advisory for Siemens TeleControl Server Basic
CISA published ICS advisory ICSA-25-289-09 for Siemens TeleControl Server Basic, corresponding to the previously disclosed CVE-2025-40765 information disclosure issue. The advisory formally notified defenders and ICS operators of the affected product and associated risk.
CISA publishes 13 ICS advisories including Siemens and Rockwell issues
CISA released thirteen Industrial Control Systems advisories covering vulnerabilities and security issues across products from Siemens, Rockwell Automation, Hitachi Energy, Schneider Electric, and Delta Electronics. The advisories provided technical details and mitigation guidance for affected OT and ICS environments.
CVE-2025-40765 for Siemens TeleControl Server Basic is disclosed
A high-severity information disclosure vulnerability, CVE-2025-40765, affecting Siemens TeleControl Server Basic was publicly listed. The reference indicates public disclosure of the CVE before broader CISA advisory coverage.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
11 references tracked. Mallory keeps watching after this page renders.
CISA Releases Thirteen Industrial Control Systems Advisories
cisa.gov
Open sourceSiemens TeleControl Server Basic
cisa.gov
Open sourceRockwell Automation FactoryTalk ViewPoint
cisa.gov
Open sourceSiemens SiPass Integrated
cisa.gov
Open sourceRockwell Automation FactoryTalk View Machine Edition and PanelView Plus 7
cisa.gov
Open sourceSiemens Solid Edge
cisa.gov
Open sourceSiemens SINEC NMS
cisa.gov
Open sourceCVE-2025-40765 - "TeleControl Server Basic Information Disclosure Vulnerability"
cvefeed.io
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


