{"id":2846,"date":"2025-03-26T10:04:04","date_gmt":"2025-03-26T10:04:04","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/03\/26\/cisa-warns-of-four-vulnerabilities-and-exploits-surrounding-ics\/"},"modified":"2025-03-26T10:04:04","modified_gmt":"2025-03-26T10:04:04","slug":"cisa-warns-of-four-vulnerabilities-and-exploits-surrounding-ics","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/03\/26\/cisa-warns-of-four-vulnerabilities-and-exploits-surrounding-ics\/","title":{"rendered":"CISA Warns of Four Vulnerabilities, and Exploits Surrounding ICS"},"content":{"rendered":"<p>    CISA Warns of Four Vulnerabilities, and Exploits Surrounding ICS<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Cybersecurity and Infrastructure Security Agency (CISA) released four <a href=\"https:\/\/cybersecuritynews.com\/cisa-releases-five-industrial-control-systems\/\" target=\"_blank\" rel=\"noreferrer noopener\">Industrial Control System (ICS) advisories<\/a> on March 25, 2025, detailing significant vulnerabilities in products from ABB, Rockwell Automation, and Inaba Denki Sangyo.\u00a0<\/p>\n<p>These vulnerabilities, with CVSS v4 scores ranging from 5.1 to 9.3, could allow attackers to cause denial of service, execute arbitrary commands, take over devices, or gain unauthorized access.\u00a0<\/p>\n<p>The affected systems are deployed in critical infrastructure sectors, including oil and gas, manufacturing, and commercial facilities worldwide, making these vulnerabilities particularly concerning.<\/p>\n<h2 class=\"wp-block-heading\"><strong>ABB RMC-100 (ICSA-25-084-01)<\/strong><\/h2>\n<p>CISA\u2019s first advisory concerns the ABB RMC-100 flow computer used in oil and gas measurement systems.\u00a0<\/p>\n<p>The vulnerability (CVE-2022-24999) involves prototype pollution in the <a href=\"https:\/\/cybersecuritynews.com\/ibm-watsonx-ai-xss-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">web UI<\/a> (REST interface) with a CVSS v4 score of 8.7.\u00a0<\/p>\n<p>Affecting versions 2105457-036 to 2105457-044 of RMC-100 and versions 2106229-010 to 2106229-016 of RMC-100 LITE, an attacker could send specially crafted messages causing a denial of service that requires restarting the interface.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\">Stop attacks before they start, powered by a 97% precise neural Network to <strong><a href=\"https:\/\/firstwatch.whoisxmlapi.com\/?utm_campaign=9753186-Cyber%20Security%20News&amp;utm_source=email&amp;utm_medium=paidemail&amp;utm_content=csn2_websitevisit\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Detect Cyber Attacks<\/a><\/strong><\/p>\n<p>ABB recommends updating to newer versions (RMC-100 Customer Package 2105452-048 or RMC-100 LITE Customer Package 2106260-017) and disabling the REST interface when not configuring MQTT functionality.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Rockwell Automation Verve Asset Manager (ICSA-25-084-02)<\/strong><\/h2>\n<p>The second advisory addresses Rockwell Automation\u2019s Verve Asset Manager, versions 1.39 and prior.\u00a0<\/p>\n<p>The vulnerability (CVE-2025-1449, CWE-1287) stems from insufficient variable sanitizing in the administrative web interface for the Legacy Active Directory Interface.\u00a0<\/p>\n<p>With a CVSS v4 score of 8.9, an attacker with administrative access could run arbitrary commands in the container running the service. The Legacy ADI capability has been deprecated since version 1.36. <\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/rockwell-automation-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">Rockwell Automation<\/a> has released version 1.40 to address the vulnerability and recommends users implement security best practices, including network isolation and using secure remote access methods.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Rockwell Automation 440G TLS-Z (ICSA-25-084-03)<\/strong><\/h2>\n<p>The third advisory concerns Rockwell Automation\u2019s 440G TLS-Z safety device, version v6.001. The vulnerability (CVE-2020-27212, CWE-74) exists in the STMicroelectronics STM32L4 component, which has incorrect access controls.\u00a0<\/p>\n<p>With a CVSS v4 score of 7.3, an attacker with physical access and high technical capability could reverse protections controlling the JTAG interface, potentially leading to a complete device takeover.\u00a0<\/p>\n<p>Unlike the other vulnerabilities, this is not remotely exploitable and requires physical access. Rockwell Automation recommends limiting physical access to authorized personnel only and implementing security best practices outlined in their System Security Design Guidelines<\/p>\n<h2 class=\"wp-block-heading\"><strong>Inaba Denki Sangyo CHOCO TEI WATCHER Mini (ICSA-25-084-04)<\/strong><\/h2>\n<p>The fourth advisory <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/03\/25\/cisa-releases-four-industrial-control-systems-advisories\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reveals<\/a> multiple vulnerabilities in all versions of the Inaba Denki Sangyo CHOCO TEI WATCHER mini (IB-MCT001), a device used in manufacturing environments.\u00a0<\/p>\n<p>The vulnerabilities include client-side authentication (CVE-2025-24517, CVSS v4: 8.7), storing passwords in recoverable format (CVE-2025-24852, CVSS v4: 5.1), weak password requirements (CVE-2025-25211, CVSS v4: 9.3), and forced browsing (CVE-2025-26689, CVSS v4: 9.3).\u00a0<\/p>\n<p>These vulnerabilities could allow attackers to obtain passwords, gain unauthorized access, and modify data or settings.\u00a0<\/p>\n<p>No patches are available; Inaba Denki Sangyo recommends using the product within a secure LAN, implementing firewalls\/VPNs, and restricting physical access to authorized users.<\/p>\n<p>These advisories highlight the ongoing challenges in securing industrial control systems as IT and OT environments converge.\u00a0<\/p>\n<h2 class=\"wp-block-heading\"><strong>Mitigation<\/strong><\/h2>\n<p>CISA recommends several common mitigation strategies: promptly applying patches where available (ABB and Rockwell Automation products), implementing network segmentation to isolate critical systems, using secure methods for remote access, and limiting physical access to devices (particularly for the Rockwell 440G TLS-Z).\u00a0<\/p>\n<p>For unpatched systems like the CHOCO TEI WATCHER mini, network isolation becomes even more critical.\u00a0<\/p>\n<p>Organizations should conduct thorough risk assessments before implementing defensive measures and report any suspected malicious activity to <a href=\"https:\/\/cybersecuritynews.com\/cisa-releases-five-industrial-control-systems\/\" target=\"_blank\" rel=\"noreferrer noopener\">CISA<\/a>. No public exploitation of these vulnerabilities has been reported at this time.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><code><strong><code>Investigate Real-World Malicious Links &amp; Phishing Attacks With\u00a0<strong>Threat Intelligence Lookup<\/strong>\u00a0-\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=enrichment&amp;utm_content=plans&amp;utm_term=180325\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for Free<\/a><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisa-warns-of-four-vulnerabilities-and-exploits\/\">CISA Warns of Four Vulnerabilities, and Exploits Surrounding ICS<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisa-warns-of-four-vulnerabilities-and-exploits\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Warns of Four Vulnerabilities, and Exploits Surrounding ICS The Cybersecurity and Infrastructure Security Agency (CISA) released four Industrial Control System (ICS) advisories on March 25, 2025, detailing significant vulnerabilities in products from ABB, Rockwell Automation, and Inaba Denki Sangyo.\u00a0 These vulnerabilities, with CVSS v4 scores ranging from 5.1 to 9.3, could allow attackers to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,416,131],"tags":[130],"class_list":["post-2846","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerabilities","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2846"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2846"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2846\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2846"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2846"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2846"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}