CISA Adds CVE-2025-58034 to Known Exploited Vulnerabilities Catalog
CISA has added CVE-2025-58034 to its Known Exploited Vulnerabilities Catalog amid active exploitation, urging organizations to act.
Decision Insights Threat Desk • November 18, 2025
CISA has added CVE-2025-58034 to its Known Exploited Vulnerabilities Catalog amid active exploitation, urging organizations to act.
Decision Insights Threat Desk • November 18, 2025
A vulnerability affecting Shelly Pro 4PM smart switches (versions prior to v1.6) has been reported, allowing potential Denial of Service conditions due to memory overallocation. Users are advised to update their devices and follow CISA's mitigation recommendations.
Decision Insights Threat Desk • November 18, 2025
CISA issued six new Industrial Control Systems Advisories detailing vulnerabilities and exploits related to various ICS products. The advisories include information on products from Schneider Electric and Shelly, among others. Users and administrators are advised to review these advisories for technical details and mitigations.
Decision Insights Threat Desk • November 18, 2025
Schneider Electric has issued a security alert for vulnerabilities in EcoStruxure Machine SCADA Expert and Pro-face BLUE Open Studio related to cryptographic algorithms. Users are advised to update to version 2023.1 Patch 1 or apply risk mitigations to safeguard sensitive data.
Decision Insights Threat Desk • November 18, 2025
Schneider Electric disclosed vulnerabilities in PowerChute Serial Shutdown versions 1.3 and prior, rated CVSS 7.8. Issues include path traversal, excessive authentication attempts, and incorrect permissions. Users should upgrade to version 1.4 to mitigate risks. CISA recommends several defensive measures.
Decision Insights Threat Desk • November 18, 2025
The report details a vulnerability in the Shelly Pro 3EM smart DIN rail switch, indicating a CVSS v4 score of 8.3 due to potential Denial of Service conditions. Mitigation recommendations include securing network exposure and employing firewalls and VPNs. No public exploitation has been reported.