Vulnerabilities are weaknesses or flaws in systems, software, hardware, configurations, or processes that adversaries can exploit to compromise confidentiality, integrity, or availability. The concept underpins vulnerability management, regulatory compliance, risk assessment, and security investment decisions across enterprise IT, cloud, and operational technology environments.
CISA issued six new Industrial Control Systems Advisories detailing vulnerabilities and exploits related to various ICS products. The advisories include information on products from Schneider Electric and Shelly, among others. Users and administrators are advised to review these advisories for technical details and mitigations.
Schneider Electric has issued a security alert for vulnerabilities in EcoStruxure Machine SCADA Expert and Pro-face BLUE Open Studio related to cryptographic algorithms. Users are advised to update to version 2023.1 Patch 1 or apply risk mitigations to safeguard sensitive data.
Schneider Electric disclosed vulnerabilities in PowerChute Serial Shutdown versions 1.3 and prior, rated CVSS 7.8. Issues include path traversal, excessive authentication attempts, and incorrect permissions. Users should upgrade to version 1.4 to mitigate risks. CISA recommends several defensive measures.
The report details a vulnerability in the Shelly Pro 3EM smart DIN rail switch, indicating a CVSS v4 score of 8.3 due to potential Denial of Service conditions. Mitigation recommendations include securing network exposure and employing firewalls and VPNs. No public exploitation has been reported.
CISA has added CVE-2025-21042, an Out-of-Bounds Write Vulnerability in Samsung Mobile Devices, to its Known Exploited Vulnerabilities Catalog. Federal agencies are mandated to remediate such vulnerabilities to safeguard networks. CISA recommends all organizations prioritize timely remediation of these vulnerabilities.
CISA has identified exploitation of CVE-2025-64446 in Fortinet's FortiWeb, affecting several versions. Organizations must upgrade or disable HTTP/HTTPS for exposed systems.