Vulnerabilities are weaknesses or flaws in systems, software, hardware, configurations, or processes that adversaries can exploit to compromise confidentiality, integrity, or availability. The concept underpins vulnerability management, regulatory compliance, risk assessment, and security investment decisions across enterprise IT, cloud, and operational technology environments.
CISA added CVE-2025-64446, a Fortinet FortiWeb path traversal vulnerability, to its Known Exploited Vulnerabilities Catalog due to active exploitation evidence. Federal agencies must remediate under BOD 22-01; CISA recommends all organizations prioritize mitigation of listed vulnerabilities in vulnerability management.
As of January 10, 2023, CISA will cease updates for Siemens product vulnerabilities. Multiple vulnerabilities affecting Siemens LOGO! 8 BM Devices have been reported, allowing for potential remote code execution and device manipulation. Mitigations have been suggested while Siemens prepares fixes.
Rockwell Automation's Verve Asset Manager has a vulnerability, CVE-2025-11862, identified as incorrect authorization, affecting multiple versions. Users are advised to update to versions 1.41.4 and 1.42. CISA recommends defensive measures to reduce exploitation risks.
CISA will cease updates on Siemens ICS security advisories for product vulnerabilities, initially reporting on issues affecting the SICAM P850 and P855 families, specifically vulnerabilities related to CSRF and incorrect permission assignments. Users are encouraged to update and implement security measures to mitigate risks.
Rockwell Automation identified a vulnerability in FactoryTalk Policy Manager that may allow remote exploitation leading to Denial of Service. Versions 6.51.00 and prior are affected, with a fix available in 6.60.00 and later. Users are advised to implement security best practices.
Rockwell Automation's Studio 5000 Simulation Interface has vulnerabilities allowing unauthorized access and potential exploitation. Users are advised to upgrade to version 3.0.0 or later to mitigate risks associated with path traversal and SSRF vulnerabilities. CISA offers defensive measures and best practices for cyber defense.
AVEVA has reported a vulnerability in its Application Server Immutable Deployment Environment that could allow attackers to exploit improper HTML script neutralization. Users are advised to update to secure versions and implement defensive measures to minimize risk.