CISA Releases 18 Industrial Control Systems Advisories
CISA has released 18 advisories concerning security issues, vulnerabilities, and exploits in various Industrial Control Systems (ICS).
Decision Insights Threat Desk • November 20, 2025
CISA has released 18 advisories concerning security issues, vulnerabilities, and exploits in various Industrial Control Systems (ICS).
Decision Insights Threat Desk • November 20, 2025
As of January 10, 2023, CISA will cease updates for Siemens product vulnerabilities. Multiple vulnerabilities affecting Siemens LOGO! 8 BM Devices have been reported, allowing for potential remote code execution and device manipulation. Mitigations have been suggested while Siemens prepares fixes.
Decision Insights Threat Desk • November 20, 2025
Rockwell Automation's Verve Asset Manager has a vulnerability, CVE-2025-11862, identified as incorrect authorization, affecting multiple versions. Users are advised to update to versions 1.41.4 and 1.42. CISA recommends defensive measures to reduce exploitation risks.
Decision Insights Threat Desk • November 20, 2025
CISA will cease updates on Siemens ICS security advisories for product vulnerabilities, initially reporting on issues affecting the SICAM P850 and P855 families, specifically vulnerabilities related to CSRF and incorrect permission assignments. Users are encouraged to update and implement security measures to mitigate risks.
Decision Insights Threat Desk • November 20, 2025
Rockwell Automation identified a vulnerability in FactoryTalk Policy Manager that may allow remote exploitation leading to Denial of Service. Versions 6.51.00 and prior are affected, with a fix available in 6.60.00 and later. Users are advised to implement security best practices.
Decision Insights Threat Desk • November 20, 2025
Rockwell Automation's Studio 5000 Simulation Interface has vulnerabilities allowing unauthorized access and potential exploitation. Users are advised to upgrade to version 3.0.0 or later to mitigate risks associated with path traversal and SSRF vulnerabilities. CISA offers defensive measures and best practices for cyber defense.