CISA Issues ICS Advisories Addressing Vulnerabilities

CISA Issues ICS Advisories Addressing Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has issued two urgent advisories today, highlighting significant security flaws within Industrial Control Systems (ICS) that could jeopardize a variety of critical infrastructure sectors, including healthcare, manufacturing, energy, transportation, and water utilities.

The advisories, marked as ICSA-25-121-01 and ICSMA-25-121-01, offer essential insights into vulnerabilities affecting KUNBUS GmbH’s Revolution Pi and the MicroDicom DICOM Viewer. These issues pose a risk of exploitation and could cause considerable disruptions if not promptly addressed.

Critical Security Gaps in KUNBUS Revolution Pi Expose Infrastructure to Remote Threats

The first advisory (ICSA-25-121-01) pertains to multiple security flaws within the Revolution Pi industrial automation platform, produced by KUNBUS GmbH. One of the most pressing vulnerabilities, CVE-2025-35996, enables attackers to bypass authentication, granting unauthorized access to systems. In addition, CVE-2025-36558, linked to improper server-side script neutralization, could open the door for cross-site scripting (XSS) attacks if left unpatched.

The advisory highlights that PiCtory versions 2.11.1 and earlier are particularly at risk. As of now, KUNBUS has not issued any patches, leaving numerous devices in critical infrastructure sectors like water treatment, power distribution, and manufacturing exposed to potential attacks.

These vulnerabilities were discovered by Adam Bromiley from Pen Test Partners and reported to CISA.

Healthcare Systems at Risk Due to MicroDicom DICOM Viewer Vulnerabilities

The second advisory (ICSMA-25-121-01) addresses security issues in MicroDicom DICOM Viewer, a widely used application in medical environments for viewing diagnostic images. CISA has identified two severe vulnerabilities: CVE-2025-35975, an out-of-bounds write flaw, and CVE-2025-36521, an out-of-bounds read flaw. Both of these flaws could enable attackers to execute arbitrary code by manipulating specially crafted DICOM files.

Users are urged to update to version 2025.2 or later to mitigate these risks. These vulnerabilities were reported by Michael Heinzl.

CISA’s Mitigation Recommendations

In response to these vulnerabilities, CISA recommends several key security measures, including minimizing network exposure for ICS, isolating control systems behind dedicated firewalls, and using secure access methods such as VPNs for remote connections. Additionally, organizations are advised to implement layered security strategies (defense-in-depth) to reduce potential attack surfaces.

The agency also emphasizes the importance of conducting thorough risk assessments before implementing mitigation strategies.

At this time, CISA has not observed any public exploitation of these vulnerabilities. However, organizations are strongly encouraged to review the full advisories on CISA’s website for in-depth technical guidance and recommended actions.

CISA continues to monitor the situation and will issue updates as new information becomes available.

More Articles & Posts