CA-FORESCOUT
6.12.2023 07:02:34 CET | Business Wire | Press release
Forescout, a global cybersecurity leader, today released “SIERRA:21 – Living on the Edge,” an analysis of 21 newly discovered vulnerabilities within OT/IoT routers and open-source software components. The report — produced by Forescout Research – Vedere Labs, a leading global team dedicated to uncovering vulnerabilities in critical infrastructure — emphasizes the continued risk to critical infrastructure and sheds light on possible mitigations.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231205915662/en/
Sierra:21 Infographic (Source: Forescout)
“SIERRA:21 – Living on the Edge” features research into Sierra Wireless AirLink cellular routers and some of its open-source components, such as TinyXML and OpenNDS. Sierra Wireless routers are popular — an open database of Wi-Fi networks shows 245,000 networks worldwide running Sierra Wireless for a variety of applications. For example, Sierra Wireless routers are used for police vehicles connecting to a central network management system or to stream surveillance video, in manufacturing plants for industrial asset monitoring, in healthcare facilities providing temporary connectivity and to manage electric vehicle charging stations. The 21 new vulnerabilities have the potential to stop vital communications that could impact everyday life.
Read the blog: Forescout Vedere Labs discloses 21 new vulnerabilities affecting OT/IoT routers
Forescout Research further finds:
- The attack surface is expansive with 86,000 vulnerable routers still exposed online. Less than 10% of these routers are confirmed to be patched against known previous vulnerabilities found since 2019.
-
Regions with the highest number of exposed devices includes:
- 68,605 devices in The United States
- 5,580 devices in Canada
- 3,853 devices in Australia
- 2,329 devices in France
- 1,001 devices in Thailand
- Among the 21 vulnerabilities, one has critical severity (CVSS score 9.6), nine have high severity and 11 have medium severity. These vulnerabilities allow attackers to steal credentials, take control of a router by injecting malicious code, persist on the device and use it as an initial access point into critical networks.
- Patching can’t fix everything. 90 percent of devices exposing a specific management interface have reached end of life, meaning they cannot be further patched.
- It’s an uphill battle to secure supply chain components. Open-source software elements continue to go unchecked and increase the attack surface of critical devices, leading to vulnerabilities that may be hard for organizations to track and mitigate.
“We are raising the alarm today because there remain thousands of OT/IoT devices representing an increased attack surface that requires attention,” advises Elisa Constante, VP of Research, Forescout Research – Vedere Labs. “Vulnerabilities impacting critical infrastructure are like an open window for bad actors in every community. State-sponsored actors are developing custom malware to use routers for persistence and espionage. Cybercriminals are also leveraging routers and related infrastructure for residential proxies and to recruit into botnets. Our discoveries reaffirm the need for heightened awareness of the OT/IoT edge devices that are so often neglected.”
Sierra Wireless and OpenDNS have issued patches for the identified vulnerabilities. TinyXML is an abandoned open source project, so the upstream vulnerabilities will not be fixed and must be addressed downstream.
For more information, download the full report, “SIERRA:21 – Living on the Edge,” now at https://www.forescout.com/resources/sierra21-vulnerabilities.
Additional Resources:
- View the on-demand webinar: https://www.brighttalk.com/central/account/616385/channel/13809/video/602171
- Read more insight from Forescout Research: Hacktivists attack U.S. water treatment plant – analysis and implications
About Forescout
Forescout Technologies, Inc., a global cybersecurity leader, continuously identifies, protects and helps ensure the compliance of all managed and unmanaged connected cyber assets – IT, IoT, IoMT and OT. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide vendor-agnostic, automated cybersecurity at scale. The Forescout® Platform delivers comprehensive capabilities for network security, risk and exposure management, and extended detection and response. With seamless context sharing and workflow orchestration via ecosystem partners, it enables customers to more effectively manage cyber risk and mitigate threats.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20231205915662/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Brightfin Launches Spend Clearly AI to Help Enterprise Tech Leaders Take Control of Growing IT and AI Costs6.5.2026 22:32:00 CEST | Press release
New AI-powered optimization app delivers real-time visibility, cost reduction, and predictive forecasting as enterprise AI spending accelerates Brightfin, a leader in AI native IT cost optimization, today announced the launch of Spend Clearly AI, an intelligent optimization app purpose-built for enterprise technology leaders navigating the dual pressures of rising IT complexity and rapidly escalating AI investment. As organizations race to deploy AI apps, models, and infrastructure, technology demands on the budget are expanding faster than ever and growing harder to track, justify, and control. The modern enterprise IT bill has become a moving target. Spend Clearly AI gives CIOs, CTOs, and IT finance teams a single, intelligent app to see exactly where every technology dollar is going, eliminate waste, and stay ahead of costs before they spiral. "Stop thinking about IT as a cost problem. The goal isn't just to spend less — the goal is to spend better," said Joel Martins, CEO of Bright
iQmetrix to Showcase Intelligent Commerce Operating System and Catalyst Innovation at DTW Ignite 20266.5.2026 19:20:00 CEST | Press release
Bronze sponsor debut includes Catalyst project innovation, live platform demo, and a unified AI‑native commerce vision iQmetrix, the Intelligent Commerce Operating System for telecom, announced today it will exhibit, speak, and compete as a bronze sponsor at DTW Ignite 2026 in Copenhagen from June 23–25. The company will deliver a live product demo in The Loft, showcase its ODA PRISM Catalyst project alongside a consortium of global operators and technology partners, and exhibit at Booth #317 throughout the event. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260506948390/en/ The debut marks a milestone in iQmetrix’s global growth strategy and deepens its partnership with TM Forum, following its recent recognition as an ODA Component Directory Partner. The Future of Commerce Is Won at the Orchestration Layer DTW Ignite 2026’s theme, “The Future. Faster.,” captures the urgency facing communications service providers worldwid
Go Beyond the Guidebook: Why Ireland Rewards Those Who Slow Down6.5.2026 18:15:00 CEST | Press release
In a world where travel often feels rushed and driven by checklists, Ireland stands apart. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260501313521/en/ Lusty Beg Island Kesh, Co. Fermanagh The destination offers something deeper, drawing visitors beyond the expected toward richer encounters with its landscapes, culture and communities. As a compact island, Ireland gives holiday makers the chance to take in much of the destination while still travelling at a relaxed, unhurried pace. It’s a chance to slow down, not to do less, but to feel more - more calm, more connection, and more of what makes travel meaningful. This approach to travel is matched by Ireland’s natural warmth and welcome, helping visitors feel at home from the moment they arrive. Take the scenic route From the rugged coastline of the Wild Atlantic Way, one of the world’s longest coastal routes, to the rolling landscapes of Ireland’s Hidden Heartlands, Irela
TACTICA AI Introduces Region’s First AI Platform for Mission-Critical, Real-Time Operational Decisions6.5.2026 17:18:00 CEST | Press release
Built on deep tech developed by TII, TACTICA AI moves beyond dashboards to help decision-makers turn fragmented intelligence, sensor, and operational data into action Showcased during Make it in the Emirates 2026, the platform has already been validated through real-world deployments in mission-critical environments Built in Abu Dhabi, connected globally, TACTICA AI integrates partnerships with French-based Safran and Polish-based Satim TACTICA AI, an Abu Dhabi-based start-up, today introduced its multi-domain decision-support platform to a wider market during Make it in the Emirates 2026. At a time of increasing operational complexity and pressure to make faster, better-informed decisions, the platform is designed to transform fragmented intelligence, sensor, and operational data into real-time decisions. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260506006177/en/ TACTICA AI Introduces Region’s First AI Platform for Mis
FlightSafety International Receives FAA Approval for Virtual Aircraft Preflight Inspection with Evaluation Mode6.5.2026 16:05:00 CEST | Press release
Three aircraft programs approved, with three more expected to receive approval in 2026 FlightSafety International Inc., the global leader in aviation training and simulation technology, today announced it has received Federal Aviation Administration (FAA) approval for Virtual Aircraft Preflight Inspection (VAPI) with Evaluation Mode for three aircraft training programs: the Embraer EMB-550, Gulfstream G500/G600, and Citation Latitude. This innovative capability allows pilots in initial training to complete a 3D virtual aircraft preflight inspection while in Training Mode, with the added ability to transition directly into the flight deck, followed by Evaluation Mode, that allows pilots to do their preflight check ride portion. “VAPI represents a meaningful advancement in training innovation,” said David Penney, VP of Safety, Courseware and Regulatory Affairs, FlightSafety International. “By leveraging an immersive 3D environment, it offers pilots a more engaging and practical way to de
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
