Vulnerabilities are weaknesses or flaws in systems, software, hardware, configurations, or processes that adversaries can exploit to compromise confidentiality, integrity, or availability. The concept underpins vulnerability management, regulatory compliance, risk assessment, and security investment decisions across enterprise IT, cloud, and operational technology environments.
CISA added CVE-2025-58034, a Fortinet FortiWeb OS command code injection vulnerability, to its Known Exploited Vulnerabilities Catalog. This vulnerability is actively exploited, with a recommended remediation timeframe of one week. Federal agencies are required to address such vulnerabilities under BOD 22-01.
A vulnerability in Shelly Pro 4PM smart DIN rail switches prior to version 1.6 allows attackers to cause denial of service by exploiting a resource allocation flaw in the JSON parser. The issue has a CVSS v4 score of 8.3. Mitigations include software updates and network security measures.
Schneider Electric's PowerChute Serial Shutdown versions 1.3 and earlier have vulnerabilities including path traversal, excessive authentication attempts, and incorrect default permissions. Version 1.4 fixes these issues. Users are advised to apply the update and follow recommended security measures to reduce risk.
CISA published six advisories on Industrial Control Systems highlighting security issues and vulnerabilities related to products from Schneider Electric, Shelly, and METZ CONNECT. The advisories provide technical details and mitigations, urging users and administrators to review them for security maintenance.
A vulnerability related to weak cryptographic algorithms in Schneider Electric's EcoStruxure Machine SCADA Expert and Pro-face BLUE Open Studio products was detailed. Patches are available in version 2023.1 Patch 1. Mitigation steps and best cybersecurity practices are recommended by Schneider Electric and CISA.
Zenitel's TCIV-3+ devices prior to version 9.3.3.0 have vulnerabilities including OS command injection, out-of-bounds write, and cross-site scripting. These issues could allow arbitrary code execution or denial of service. Mitigations include upgrading firmware and network security measures.