CISA published multiple Industrial Control Systems (ICS) advisories detailing vulnerabilities across a range of OT and connected-device products, including critical issues in AVEVA Process Optimization (multiple CVEs) that could enable unauthenticated remote code execution, SQL injection, privilege escalation, and sensitive data exposure in affected versions (<=2024.1). Additional advisories describe flaws in several Siemens product lines, including a DoS condition in SIMATIC/SIPLUS ET 200 components triggered via an S7 protocol disconnect request (CVE-2025-40944), a TLS certificate upload input-validation issue that can crash/reboot RUGGEDCOM ROS devices (CVE-2025-40935), a local privilege escalation in TeleControl Server Basic prior to V3.1.2.4 (CVE-2025-40942), and multiple issues in SINEC Security Monitor (including improper authorization in ssmctl-client file transfer and report-generation DoS; CVE-2025-40830, CVE-2025-40831). CISA also noted vulnerabilities affecting Siemens Industrial Edge ecosystems, including an authorization bypass in the Industrial Edge Device Kit (CVE-2025-40805) and authentication enforcement weaknesses on specific API endpoints in Industrial Edge Devices that could allow impersonation if an attacker knows a legitimate user identity.
Other CISA advisories covered Schneider Electric EcoStruxure Power Build Rapsody (CVE-2025-13844), where importing a malicious project file (SSD) could trigger memory corruption (e.g., double free/use-after-free) and potentially arbitrary code execution, and Rockwell Automation FactoryTalk DataMosaix Private Cloud (CVE-2025-12807), where low-privilege users could perform sensitive database operations via exposed API endpoints (SQL injection class). Separately, CISA warned about YoSmart/YoLink weaknesses (multiple CVEs) including insufficient authorization controls in the MQTT broker enabling cross-account device control when device IDs are obtained (with IDs described as predictable), plus additional issues such as cleartext transmission and predictable identifiers. A non-CISA item in the set reported Cisco releasing updates for a max-severity AsyncOS vulnerability under active exploitation (CVE-2025-20393) affecting Secure Email Gateway and Secure Email and Web Manager appliances, including evidence of attacker-installed persistence and attribution by Cisco Talos to UAT-9686; this is a separate enterprise email-security incident and not part of the ICS advisory set.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
CISA republished an AVEVA advisory describing seven vulnerabilities in AVEVA Process Optimization 2024.1 and earlier, including unauthenticated remote code execution, SQL injection, privilege escalation, and information exposure. The most severe issue was rated CVSS 10.0, and CISA said no known public exploitation had been reported.
Schneider Electric disclosed double-free and use-after-free vulnerabilities in EcoStruxure Power Build Rapsody that can be triggered when a user imports a malicious project file, potentially causing heap corruption or arbitrary code execution. Schneider said fixes were available and credited both internal and external researchers for reporting the issues.
Siemens disclosed CVE-2025-40805 in Industrial Edge Device Kit, a critical authorization bypass that lets an unauthenticated remote attacker impersonate a legitimate user on certain API endpoints if the attacker knows a valid user identity. Siemens released new versions for several affected arm64 and x86-64 builds and provided mitigations for others.
Siemens disclosed a critical authentication and authorization weakness across multiple Industrial Edge and related SIMATIC and SCALANCE products that allows unauthenticated remote impersonation of a legitimate user if a valid identity is known. Siemens provided fixes for many product lines, though some products had no fix available at the time.
Nozomi Networks published four vulnerabilities affecting Guardian/CMC, and Siemens issued an advisory stating that RUGGEDCOM APE1808 devices are impacted. The issues included stored HTML injection/XSS and a path traversal flaw, while Siemens said fixed versions were still being prepared.
Siemens disclosed two medium-severity flaws in SINEC Security Monitor before version 4.10.0, including arbitrary file read/write via the ssmctl-client file_transfer feature and a report-generation denial of service. Siemens released version 4.10.0 and recommended upgrading.
Siemens disclosed CVE-2025-40935, a medium-severity vulnerability in RUGGEDCOM ROS devices that can cause a temporary denial of service during TLS certificate upload by crashing and rebooting the device. Siemens released updated versions and recommended customers upgrade.
Siemens disclosed CVE-2025-40942 in TeleControl Server Basic before version 3.1.2.4, a high-severity local privilege escalation issue that could enable arbitrary code execution with elevated privileges. Siemens released version 3.1.2.4 and advised customers to update.
Siemens disclosed CVE-2025-40944, a high-severity denial-of-service vulnerability in multiple SIMATIC and SIPLUS ET 200 interface modules and couplers that can be triggered with a valid S7 Disconnect Request. Siemens released fixes for several affected products and said additional fixes were in preparation for others.
Festo disclosed that numerous industrial automation products expose remote-accessible functions through an undocumented protocol, creating a critical unauthenticated attack path with potential full loss of confidentiality, integrity, and availability. The issue was reported by researchers from Forescout, and Festo said mitigation would come through updated technical documentation in a future product version.
CISA published an advisory covering multiple vulnerabilities in the YoSmart/YoLink ecosystem, including cross-account device control, sensitive data interception, session hijacking, and long-lived session tokens. Affected components included the YoLink Smart Hub, mobile app, server, and MQTT broker, with no known public exploitation reported at the time.
CISA republished an advisory for CVE-2025-12807 affecting Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 7.11, 8.00, and 8.01. The high-severity SQL injection flaw could let low-privilege users perform sensitive database operations, and CISA said it had no reports of public exploitation at publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.