Cognex has confirmed that nearly a dozen serious security vulnerabilities affecting its IS2000M-120 industrial smart cameras will not be patched, citing the product's age as the primary reason. Security researchers from Nozomi Networks identified nine distinct flaws during a comprehensive assessment of the IS2000M-120, a device widely used in manufacturing environments for tasks such as part inspection, presence detection, and barcode reading. The vulnerabilities could allow attackers to fully compromise the affected cameras, potentially leading to significant operational disruptions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a public advisory on September 18, warning that exploitation of these flaws could halt production lines, damage equipment, or compromise safety-critical processes, even though the cameras themselves do not store sensitive data or serve as core network infrastructure. The research highlighted that the In-Sight Explorer platform, which is used to configure and manage these cameras, is particularly susceptible. Attackers on the same network could exploit weaknesses in the In-Sight protocol to intercept and reuse encrypted credentials, bypassing authentication controls. All three protocols used by the camera for authentication share the same flawed method, increasing the risk of unauthorized access. Despite the IS2000M-120 still being commercially available, Cognex has indicated it is considering end-of-life status for the device and is encouraging customers to purchase newer models instead of providing a security update. This decision has raised concerns among industrial operators who rely on these cameras for automation and quality control. The lack of a patch leaves organizations with limited mitigation options, primarily involving network segmentation and device isolation to reduce exposure. Security experts warn that unpatched vulnerabilities in operational technology can have cascading effects on industrial processes, especially when devices are deeply integrated into production environments. The incident underscores the ongoing challenge of securing legacy industrial devices that remain in active use but are no longer supported by vendors. CISA and Nozomi Networks both recommend that affected organizations assess their risk posture and consider replacing vulnerable devices as soon as feasible. The situation highlights the importance of lifecycle management and vendor support commitments in industrial cybersecurity planning. Organizations are urged to review their asset inventories and prioritize remediation or replacement of unsupported devices. The case also serves as a reminder that even devices not directly handling sensitive data can pose significant operational risks if compromised. Industrial security teams should remain vigilant for advisories related to legacy equipment and proactively engage with vendors regarding support timelines. The Cognex IS2000M-120 vulnerabilities exemplify the broader issue of unpatched legacy systems in critical infrastructure sectors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Cognex stated it does not plan to develop patches for the IS2000M-120 vulnerabilities, describing the model as too old and considering it for end-of-life status despite it still being commercially available. This left mitigations such as network isolation as the primary defensive measure.
On 2025-09-18, CISA warned that exploitation of the Cognex camera flaws could disrupt manufacturing automation, halt production lines, damage equipment, or affect safety-critical processes. The agency recommended isolating the devices from the internet and using firewall and VPN protections.
Nozomi Networks found nine serious flaws affecting the Cognex IS2000M-120 industrial smart camera and the associated In-Sight Explorer management platform. The issues could enable credential replay, privilege escalation, tampering with backup jobs, and potentially full device compromise.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.