Skip to content

CISA flags ICS vulnerabilities in products from Siemens, Schneider Electric, Rockwell, and others

Industrialcyber.Co • December 19, 2025

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday released nine ICS (industrial control systems) advisories warning the critical infrastructure sector of hardware vulnerabilities affecting products from Inductive Automation, Schneider Electric, National Instruments, Mitsubishi Electric, Siemens, Advantech, Rockwell Automation, and Axis Communications. The advisories outline active security issues and known vulnerabilities, providing operators with timely guidance on risks and potential exploitation in ICS environments.

In an advisory, CISA warned that a vulnerability with a CVSS v3 score of 6.4 affects Inductive Automation’s Ignition platform, where execution with unnecessary privileges could allow an attacker to gain elevated access. “Successful exploitation of this vulnerability could allow an attacker to be granted direct SYSTEM-level code execution on the host operating system running the Ignition Gateway service on Windows systems.”

These products are typically used across the critical manufacturing, energy, and IT sectors. Momen Eldawakhly of Samurai Digital Security Ltd reported this vulnerability to CISA.

“The vulnerability affects Ignition SCADA applications where Python scripting is utilized for automation purposes. The vulnerability arises from the absence of proper security controls that restrict which Python libraries can be imported and executed within the scripting environment,” the advisory identified. “The core issue lies in the Ignition service account having system permissions beyond what an Ignition privileged user requires. When an authenticated administrator uploads a malicious project file containing Python scripts with bind shell capabilities, the application executes these scripts with the same privileges as the Ignition Gateway process, which typically runs with SYSTEM-level permissions on Windows. Alternative code execution patterns could lead to similar results.”

CISA disclosed that Schneider Electric is aware of a vulnerability identified by Microsoft in Windows Server Update Services (WSUS) used by EcoStruxure Foxboro DCS Advisor services. EcoStruxure Foxboro DCS Advisor, an optional component of the EcoStruxure Foxboro DCS system, enables remote connectivity and diagnostics by continuously monitoring key performance indicators across I/A Series and Control Software process environments.

CISA assigned the vulnerability a CVSS v3 score of 9.8 and classified it as a deserialization of untrusted data issue affecting Schneider Electric EcoStruxure Foxboro DCS Advisor. The product is used within critical infrastructure sectors, including critical manufacturing and energy, and is deployed worldwide. The agency warned that failure to apply the recommended mitigations could expose affected systems to remote code execution, potentially allowing unauthorized actors to obtain system-level privileges.

In another advisory, CISA revealed the presence of nine vulnerabilities with a CVSS v3 score of 7.8 that affect National Instruments LabView and include multiple issues, such as out-of-bounds write and read flaws, use-after-free conditions, and a stack-based buffer overflow. Michael Heinzl reported these vulnerabilities to CISA.

Deployed across the critical manufacturing, defense industrial base, IT, and transportation systems, the agency noted, “Successful exploitation of these vulnerabilities could allow an attacker to disclose information and execute arbitrary code.”

CISA identified a vulnerability affecting products from Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric. The issue, tracked as CVE-2025-11774, impacts several products, including GENESIS64, ICONICS Suite, MobileHMI, and MC Works64. CISA assigned the vulnerability a CVSS v3 score of 8.2 and classified it as an improper neutralization of special elements in an operating system command, commonly referred to as OS command injection.

“Malicious code execution vulnerability exists in the software keyboard function (hereinafter referred to as ‘keypad function’) of ICONICS Suite, GENESIS64, MobileHMI, and MC Works64, which could lead to denial-of-service (DoS), information tampering, and information disclosure,” the advisory said.

It added that, “An attacker may be able to execute arbitrary executable files (EXE) when a legitimate user uses the keypad function by tampering with the configuration file for the keypad function. This could allow the attacker to disclose, tamper with, delete, or destroy information stored on the PC where the affected product is installed, or cause a denial-of-service (DoS) condition on the system, through the execution of the EXE.”

Mitsubishi Electric Iconics Digital Solutions recommends users of GENESIS64, IONICS Suite, or MobileHMI upgrade to the GENESIS64 v10.97.3 or higher, or upgrade to the latest product, GENESIS V11, which all contain the fix for this vulnerability. The update can be downloaded through the ICONICS Community Portal by navigating to Resources, Product Downloads, and then selecting version 10.97.3. The latest patch for GENESIS64 version 10.97.3 is available as a critical fixes rollup from the Community Portal.

Mitsubishi Electric Iconics Digital Solutions has confirmed that there are no plans to release a fixed version of MC Works64 and recommends that users migrate to GENESIS64 version 10.97.3 or later.

To reduce the risk of exploitation, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric advise users to operate affected systems within a local area network and block remote access from untrusted networks, hosts, and users. Remote connectivity should be limited to trusted users through the use of firewalls or virtual private networks, particularly when systems are connected to the internet. Physical access to affected PCs and their connected networks should also be restricted to prevent unauthorized access.

Users are further advised to avoid clicking links or opening attachments in emails from untrusted sources, to install antivirus software on affected systems, and to consult the ICONICS whitepaper on security vulnerabilities for additional guidance. Information on the availability of security updates is provided in Mitsubishi Electric’s security advisory.

In a separate advisory, CISA warned that multiple industrial products are affected by a vulnerability in the Siemens Interniche IP-Stack. The flaw stems from insufficient enforcement of TCP sequence number validation in certain scenarios, allowing values within an overly broad range to be accepted. An unauthenticated remote attacker could exploit this weakness to interfere with connection setup, potentially causing a denial-of-service condition.

Exploitation would require the attacker to inject precisely timed IP packets with spoofed source addresses and affect only TCP-based services. Siemens has released updated versions for several impacted products and urges customers to upgrade to the latest releases. The company is also preparing additional fixes and recommends interim countermeasures for products where patches are not yet available.

CISA reported that a vulnerability with a CVSS v3 score of 7.5 affects the Siemens Interniche IP-Stack and involves improper verification of the source of a communication channel. Siemens ProductCERT reported the vulnerability to CISA. The issue was originally disclosed to Siemens by Qian Zou, Xuewei Feng, Ke Xu, Qi Li, Xueying Li, and Gang Jin of Zhongguancun Laboratory, as well as by the same researchers from Tsinghua University.

In another advisory, CISA reported that Advantech WebAccess/SCADA is affected by multiple vulnerabilities tracked as CVE-2025-14850, CVE-2025-14849, CVE-2025-14848, CVE-2025-46268, and CVE-2025-67653.

The flaws carry a CVSS v3 score of 8.8 and include improper limitation of pathnames to restricted directories, unrestricted upload of files with dangerous types, absolute path traversal, and improper neutralization of special elements in SQL commands, commonly known as SQL injection. Alex Wiliams of Pellera Technologies reported these vulnerabilities to CISA.

In a separate advisory, CISA warned that Rockwell Automation’s Micro820, Micro850, and Micro870 controllers are affected by vulnerabilities tracked as CVE-2025-13823 and CVE-2025-13824. The flaws carry a CVSS v3 score of 7.5 and arise from reliance on a vulnerable third-party component and the release of an invalid pointer or reference. Successful exploitation could lead to a denial-of-service condition. Rockwell Automation reported these vulnerabilities to CISA.

The advisory added that “a security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers. This issue occurs when the controllers receive multiple malformed packets during fuzzing, causing a recoverable fault.”

It also noted that “a security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with a solid red Fault LED and becomes unresponsive. Upon power cycling, the controller will enter a recoverable fault.”

CISA disclosed that multiple Axis Communications products are affected by vulnerabilities, including Axis Camera Station Pro, Axis Camera Station, and Axis Device Manager. The issues are tracked as CVE-2025-30023, CVE-2025-30025, and CVE-2025-30026 for Axis Camera Station Pro and Axis Camera Station, while Axis Device Manager is affected by CVE-2025-30023, CVE-2025-30024, and CVE-2025-30025.

CISA assigned a CVSS v3 score of 9.0 to vulnerabilities affecting Axis Communications Camera Station Pro, Camera Station, and Device Manager. The issues include deserialization of untrusted data, improper certificate validation, and an authentication bypass that can be achieved through an alternate path or communication channel. Noam Moshe of Claroty Team82 reported these vulnerabilities to CISA.

CISA recommends that organizations take defensive steps to reduce the risk of exploitation by limiting network exposure for control system devices and ensuring they are not directly accessible from the internet. Control system networks and remote assets should be placed behind firewalls and isolated from business networks. Where remote access is necessary, more secure methods such as virtual private networks should be used, with the understanding that VPNs must be kept fully updated and are only as secure as the devices connected to them.

Before deploying any defensive measures, CISA advises organizations to conduct proper impact analysis and risk assessments . The agency also points users to its control systems security recommended practices available on the ICS webpage at cisa.gov/ics, along with additional resources outlining cyber defense best practices, including guidance on defense-in-depth strategies for ICS. Further mitigation guidance is available in CISA’s technical information paper on targeted cyber intrusion detection and mitigation strategies.

Organizations that detect suspected malicious activity should follow established internal procedures and report their findings to CISA to support tracking and correlation with other incidents. CISA also urges organizations to remain vigilant against social engineering by avoiding unsolicited email links or attachments and consulting available guidance on recognizing email scams and phishing attacks. At this time, CISA reports no known public exploitation specifically targeting this vulnerability and notes that exploitation would require a high level of attack complexity.