CISA Issues Ten New Advisories for Industrial Control System Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) has released ten new security advisories addressing vulnerabilities in Industrial Control Systems (ICS). These advisories provide critical information on security issues, potential exploits, and mitigation strategies for ICS technologies widely used across manufacturing, energy, healthcare, and infrastructure sectors.
Key Affected Systems
Siemens Products
- License Server: Contains privilege management flaws (CVE-2025-29999, CVE-2025-30000) with CVSS v4 scores of 5.4 that could allow privilege escalation or arbitrary code execution.
- SIDIS Prime: Faces 13 vulnerabilities with a high CVSS v4 score of 9.1, including buffer overflows and race conditions that could enable unauthorized actions or remote code execution.
- Solid Edge: Features an Out-of-Bounds Write vulnerability (CVE-2024-54091) with CVSS v4 score of 7.32 that could allow arbitrary code execution when processing malicious X_T files.
- Industrial Edge Devices: Weak authentication in API endpoints (CVE-2024-54092, CVSS v4: 9.3) could allow authentication bypass and user impersonation.
- Insights Hub Private Cloud: Multiple Kubernetes ingress-nginx configuration vulnerabilities that could lead to code execution or exposure of cluster secrets.
- SENTRON 7KT PAC1260 Data Manager: Contains a path traversal vulnerability (CVE-2024-41792, CVSS v4: 8.6) potentially enabling unauthorized file access with root privileges.
Other Vendor Products
- Rockwell Automation Arena: Multiple high-risk vulnerabilities (CVE-2025-2285, CVE-2025-2293) with CVSS v4 scores of 8.5 that could lead to code execution or information disclosure.
- Subnet Solutions PowerSYSTEM Center: Vulnerabilities including out-of-bounds reads and untrusted data deserialization with CVSS v4 scores up to 6.9.
- ABB Arctic Wireless Gateways: Seven vulnerabilities including path traversal issues with CVSS v4 scores reaching 9.2 that could allow privilege escalation or data exposure.
- INFINITT Healthcare PACS: Picture Archiving and Communication System affected by unrestricted file upload and unauthorized access vulnerabilities (CVSS v4: 8.7) that could lead to code execution or patient data access.
Risk Assessment
These vulnerabilities present significant risks across critical infrastructure sectors. Successful exploitation could result in unauthorized system access, data manipulation, service disruption, or remote code execution—potentially affecting essential services.
Recommended Mitigations
CISA recommends that affected organizations:
- Update to the latest firmware/software versions as specified in vendor advisories
- Restrict network access to ICS devices using firewalls and secure configurations
- Avoid direct internet exposure of ICS devices
- Implement secure, updated VPNs for remote access
Organizations are urged to address these vulnerabilities promptly to protect critical infrastructure from potential exploitation.




