Signal
The full archive of enterprise technology signals: launches, funding, partnerships, advisories, and market moves across cloud, networking, cybersecurity, and AI.
The full archive of enterprise technology signals: launches, funding, partnerships, advisories, and market moves across cloud, networking, cybersecurity, and AI.
Decision Insights Editorial • November 25, 2025
A vulnerability in Shelly Pro 4PM smart DIN rail switches prior to version 1.6 allows attackers to cause denial of service by exploiting a resource allocation flaw in the JSON parser. The issue has a CVSS v4 score of 8.3. Mitigations include software updates and network security measures.
Decision Insights Editorial • November 25, 2025
A vulnerability in Shelly Pro 3EM switch allows crafted Modbus requests to trigger device reboots causing denial of service.
Decision Insights Editorial • November 25, 2025
Schneider Electric's PowerChute Serial Shutdown versions 1.3 and earlier have vulnerabilities including path traversal, excessive authentication attempts, and incorrect default permissions. Version 1.4 fixes these issues. Users are advised to apply the update and follow recommended security measures to reduce risk.
Decision Insights Editorial • November 25, 2025
CISA published six advisories on Industrial Control Systems highlighting security issues and vulnerabilities related to products from Schneider Electric, Shelly, and METZ CONNECT. The advisories provide technical details and mitigations, urging users and administrators to review them for security maintenance.
Decision Insights Editorial • November 25, 2025
A vulnerability related to weak cryptographic algorithms in Schneider Electric's EcoStruxure Machine SCADA Expert and Pro-face BLUE Open Studio products was detailed. Patches are available in version 2023.1 Patch 1. Mitigation steps and best cybersecurity practices are recommended by Schneider Electric and CISA.
Decision Insights Editorial • November 25, 2025
Rockwell Arena Simulation up to v16.20.10 has a buffer overflow allowing local code execution via malicious DOE files.