Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
industrial-control-system-vulnerabilityembedded-device-vulnerabilitywidely-deployed-product-advisoryactively-exploited-vulnerability

CISA ICS Advisories Highlight Multiple High-Impact Vulnerabilities Across Industrial and IoT Products

Updated 3mo agoFirst seen Jan 16, 202612 sources

CISA published multiple Industrial Control Systems (ICS) advisories detailing vulnerabilities across a range of OT and connected-device products, including critical issues in AVEVA Process Optimization (multiple CVEs) that could enable unauthenticated remote code execution, SQL injection, privilege escalation, and sensitive data exposure in affected versions (<=2024.1). Additional advisories describe flaws in several Siemens product lines, including a DoS condition in SIMATIC/SIPLUS ET 200 components triggered via an S7 protocol disconnect request (CVE-2025-40944), a TLS certificate upload input-validation issue that can crash/reboot RUGGEDCOM ROS devices (CVE-2025-40935), a local privilege escalation in TeleControl Server Basic prior to V3.1.2.4 (CVE-2025-40942), and multiple issues in SINEC Security Monitor (including improper authorization in ssmctl-client file transfer and report-generation DoS; CVE-2025-40830, CVE-2025-40831). CISA also noted vulnerabilities affecting Siemens Industrial Edge ecosystems, including an authorization bypass in the Industrial Edge Device Kit (CVE-2025-40805) and authentication enforcement weaknesses on specific API endpoints in Industrial Edge Devices that could allow impersonation if an attacker knows a legitimate user identity.

Other CISA advisories covered Schneider Electric EcoStruxure Power Build Rapsody (CVE-2025-13844), where importing a malicious project file (SSD) could trigger memory corruption (e.g., double free/use-after-free) and potentially arbitrary code execution, and Rockwell Automation FactoryTalk DataMosaix Private Cloud (CVE-2025-12807), where low-privilege users could perform sensitive database operations via exposed API endpoints (SQL injection class). Separately, CISA warned about YoSmart/YoLink weaknesses (multiple CVEs) including insufficient authorization controls in the MQTT broker enabling cross-account device control when device IDs are obtained (with IDs described as predictable), plus additional issues such as cleartext transmission and predictable identifiers. A non-CISA item in the set reported Cisco releasing updates for a max-severity AsyncOS vulnerability under active exploitation (CVE-2025-20393) affecting Secure Email Gateway and Secure Email and Web Manager appliances, including evidence of attacker-installed persistence and attribution by Cisco Talos to UAT-9686; this is a separate enterprise email-security incident and not part of the ICS advisory set.

Share:
CISA ICS Advisories Highlight Multiple High-Impact Vulnerabilities Across Industrial and IoT Products
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the most recent confirmed update back to the earliest known activity.

12 EVENTS
Jan 15, 20265mo ago

AVEVA Process Optimization vulnerabilities are republished by CISA

CISA republished an AVEVA advisory describing seven vulnerabilities in AVEVA Process Optimization 2024.1 and earlier, including unauthenticated remote code execution, SQL injection, privilege escalation, and information exposure. The most severe issue was rated CVSS 10.0, and CISA said no known public exploitation had been reported.

Jan 14, 20265mo ago

Schneider Electric discloses Power Build Rapsody file-import flaws

Schneider Electric disclosed double-free and use-after-free vulnerabilities in EcoStruxure Power Build Rapsody that can be triggered when a user imports a malicious project file, potentially causing heap corruption or arbitrary code execution. Schneider said fixes were available and credited both internal and external researchers for reporting the issues.

Siemens discloses critical auth bypass in Industrial Edge Device Kit

Siemens disclosed CVE-2025-40805 in Industrial Edge Device Kit, a critical authorization bypass that lets an unauthenticated remote attacker impersonate a legitimate user on certain API endpoints if the attacker knows a valid user identity. Siemens released new versions for several affected arm64 and x86-64 builds and provided mitigations for others.

Siemens discloses critical auth bypass in Industrial Edge devices

Siemens disclosed a critical authentication and authorization weakness across multiple Industrial Edge and related SIMATIC and SCALANCE products that allows unauthenticated remote impersonation of a legitimate user if a valid identity is known. Siemens provided fixes for many product lines, though some products had no fix available at the time.

Nozomi and Siemens identify RUGGEDCOM APE1808 exposure to Guardian/CMC flaws

Nozomi Networks published four vulnerabilities affecting Guardian/CMC, and Siemens issued an advisory stating that RUGGEDCOM APE1808 devices are impacted. The issues included stored HTML injection/XSS and a path traversal flaw, while Siemens said fixed versions were still being prepared.

Siemens releases fixes for SINEC Security Monitor vulnerabilities

Siemens disclosed two medium-severity flaws in SINEC Security Monitor before version 4.10.0, including arbitrary file read/write via the ssmctl-client file_transfer feature and a report-generation denial of service. Siemens released version 4.10.0 and recommended upgrading.

Siemens discloses RUGGEDCOM ROS certificate-upload DoS flaw

Siemens disclosed CVE-2025-40935, a medium-severity vulnerability in RUGGEDCOM ROS devices that can cause a temporary denial of service during TLS certificate upload by crashing and rebooting the device. Siemens released updated versions and recommended customers upgrade.

Siemens discloses TeleControl Server Basic privilege escalation flaw

Siemens disclosed CVE-2025-40942 in TeleControl Server Basic before version 3.1.2.4, a high-severity local privilege escalation issue that could enable arbitrary code execution with elevated privileges. Siemens released version 3.1.2.4 and advised customers to update.

Siemens discloses DoS flaw in SIMATIC and SIPLUS ET 200 products

Siemens disclosed CVE-2025-40944, a high-severity denial-of-service vulnerability in multiple SIMATIC and SIPLUS ET 200 interface modules and couplers that can be triggered with a valid S7 Disconnect Request. Siemens released fixes for several affected products and said additional fixes were in preparation for others.

Festo discloses undocumented remote-access protocol exposure in firmware

Festo disclosed that numerous industrial automation products expose remote-accessible functions through an undocumented protocol, creating a critical unauthenticated attack path with potential full loss of confidentiality, integrity, and availability. The issue was reported by researchers from Forescout, and Festo said mitigation would come through updated technical documentation in a future product version.

Jan 13, 20265mo ago

CISA publishes YoLink Smart Hub vulnerability advisory

CISA published an advisory covering multiple vulnerabilities in the YoSmart/YoLink ecosystem, including cross-account device control, sensitive data interception, session hijacking, and long-lived session tokens. Affected components included the YoLink Smart Hub, mobile app, server, and MQTT broker, with no known public exploitation reported at the time.

Rockwell FactoryTalk DataMosaix SQL injection advisory is republished

CISA republished an advisory for CVE-2025-12807 affecting Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 7.11, 8.00, and 8.01. The high-severity SQL injection flaw could let low-privilege users perform sensitive database operations, and CISA said it had no reports of public exploitation at publication.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

38 LINKEDOpen in app
Vulnerabilities
23 linked
DLL Hijacking / Uncontrolled Search Path Privilege Escalation in AVEVA Process OptimizationPrivilege Escalation via Project File Tampering in AVEVA Process OptimizationPrivilege Escalation via TCL Macro Script Code Injection in AVEVA Process OptimizationSQL Injection in AVEVA Process Optimization Captive HistorianCleartext Transmission of Sensitive Information in AVEVA Process OptimizationUnauthenticated RCE in AVEVA Process Optimization taoimr APIPrivilege Escalation via Embedded OLE Objects in AVEVA Process OptimizationYoSmart/YoLink long-lived session tokensPredictable YoSmart YoLink API endpoint URL derivationCross-account device control via incorrect authorization in YoSmart YoLink MQTT brokerCleartext MQTT transmission in YoSmart/YoLink ecosystemDenial of Service in Siemens SINEC Security Monitor Report Generation Date ParameterDoS via improper input validation in RUGGEDCOM ROS TLS certificate uploadImproper Authorization in Siemens SINEC Security Monitor ssmctl-client file_transferSQL Injection in Rockwell Automation FactoryTalk DataMosaix Private Cloud (exposed API endpoints)Path Traversal in Nozomi Guardian/CMC Import Arc Data ArchiveStored HTML Injection in Nozomi Guardian/CMC Time Machine Snapshot DiffStored HTML Injection in Nozomi Guardian/CMC Asset ListStored XSS in Nozomi Guardian/CMC Reports FunctionalityAuthentication Bypass in Siemens Industrial Edge Device Kit API EndpointsDoS in Siemens SIMATIC/SIPLUS ET 200 interface modules via S7 Disconnect Request (TCP/102)Local Privilege Escalation in Siemens TeleControl Server BasicDouble Free in Schneider Electric EcoStruxure Power Build Rapsody
Affected products
3 linked
Telecontrol Server BasicEcostruxure Power Build - RapsodyEcostruxure Power Build - Rapsody
Organizations
12 linked
SiemensAvevaVeracodeTrend MicroRockwell AutomationSchneider ElectricFesto SE & Co. KGBishop FoxForescoutNozomi NetworksYoSmartElex Cybersecurity INC
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.