Business Wire

CA-FORESCOUT

6.12.2023 07:02:34 CET | Business Wire | Press release

Share
Critical Infrastructure Still at High Risk: Forescout Research Spotlights 21 New Vulnerabilities

Forescout, a global cybersecurity leader, today released “SIERRA:21 – Living on the Edge,” an analysis of 21 newly discovered vulnerabilities within OT/IoT routers and open-source software components. The report — produced by Forescout Research – Vedere Labs, a leading global team dedicated to uncovering vulnerabilities in critical infrastructure — emphasizes the continued risk to critical infrastructure and sheds light on possible mitigations.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231205915662/en/

To view this piece of content from mms.businesswire.com, please give your consent at the top of this page.

Sierra:21 Infographic (Source: Forescout)

“SIERRA:21 – Living on the Edge” features research into Sierra Wireless AirLink cellular routers and some of its open-source components, such as TinyXML and OpenNDS. Sierra Wireless routers are popular — an open database of Wi-Fi networks shows 245,000 networks worldwide running Sierra Wireless for a variety of applications. For example, Sierra Wireless routers are used for police vehicles connecting to a central network management system or to stream surveillance video, in manufacturing plants for industrial asset monitoring, in healthcare facilities providing temporary connectivity and to manage electric vehicle charging stations. The 21 new vulnerabilities have the potential to stop vital communications that could impact everyday life.

Read the blog: Forescout Vedere Labs discloses 21 new vulnerabilities affecting OT/IoT routers

Forescout Research further finds:

  • The attack surface is expansive with 86,000 vulnerable routers still exposed online. Less than 10% of these routers are confirmed to be patched against known previous vulnerabilities found since 2019.
  • Regions with the highest number of exposed devices includes:
    • 68,605 devices in The United States
    • 5,580 devices in Canada
    • 3,853 devices in Australia
    • 2,329 devices in France
    • 1,001 devices in Thailand
  • Among the 21 vulnerabilities, one has critical severity (CVSS score 9.6), nine have high severity and 11 have medium severity. These vulnerabilities allow attackers to steal credentials, take control of a router by injecting malicious code, persist on the device and use it as an initial access point into critical networks.
  • Patching can’t fix everything. 90 percent of devices exposing a specific management interface have reached end of life, meaning they cannot be further patched.
  • It’s an uphill battle to secure supply chain components. Open-source software elements continue to go unchecked and increase the attack surface of critical devices, leading to vulnerabilities that may be hard for organizations to track and mitigate.

“We are raising the alarm today because there remain thousands of OT/IoT devices representing an increased attack surface that requires attention,” advises Elisa Constante, VP of Research, Forescout Research – Vedere Labs. “Vulnerabilities impacting critical infrastructure are like an open window for bad actors in every community. State-sponsored actors are developing custom malware to use routers for persistence and espionage. Cybercriminals are also leveraging routers and related infrastructure for residential proxies and to recruit into botnets. Our discoveries reaffirm the need for heightened awareness of the OT/IoT edge devices that are so often neglected.”

Sierra Wireless and OpenDNS have issued patches for the identified vulnerabilities. TinyXML is an abandoned open source project, so the upstream vulnerabilities will not be fixed and must be addressed downstream.

For more information, download the full report, “SIERRA:21 – Living on the Edge,” now at https://www.forescout.com/resources/sierra21-vulnerabilities.

Additional Resources:

About Forescout

Forescout Technologies, Inc., a global cybersecurity leader, continuously identifies, protects and helps ensure the compliance of all managed and unmanaged connected cyber assets – IT, IoT, IoMT and OT. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide vendor-agnostic, automated cybersecurity at scale. The Forescout® Platform delivers comprehensive capabilities for network security, risk and exposure management, and extended detection and response. With seamless context sharing and workflow orchestration via ecosystem partners, it enables customers to more effectively manage cyber risk and mitigate threats.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20231205915662/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

SBC Medical Appoints Sheng-FU Hsiao as CTOLeveraging Medical Big Data from 283 Global Locations and 6.63 Million Annual Patient Visits to Build a Scalable, AI-Driven Medical Management Infrastructure2.3.2026 13:00:00 CET | Press release

SBC Medical Group Holdings Incorporated (Nasdaq: SBC) (“SBC Medical” or the “Company”), a global provider of comprehensive consulting and management services to medical corporations and their clinics, today announced the appointment of Sheng-FU Hsiao as Chief Technology Officer (CTO), effective March 1, 2026. This appointment aligns with the Company’s 2026 management strategy, "Sophistication of Management Structure through AI and DX," and strengthens its leadership team to accelerate technological transformation. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260302064873/en/ SBC Medical Appoints Sheng-FU Hsiao as CTO Leveraging Medical Big Data from 283 Global Locations and 6.63 Million Annual Patient Visits to Build a Scalable, AI-Driven Medical Management Infrastructure SBC Medical is transitioning from a traditional labor-intensive management model to an AI-driven infrastructure to address structural challenges in the m

SIMO Expands Carrier Enablement Strategy to Power Resilient, Multi-Network Enterprise Fixed Wireless Access Deployments2.3.2026 13:00:00 CET | Press release

xSIM orchestration delivers cross-network performance and unified global FWA deployment. SIMO, a leader in innovative mobile connectivity solutions, today announced the expansion of its carrier enablement strategy to power resilient, multi-network enterprise Fixed Wireless Access (FWA) deployments for both primary and backup applications. SIMO will showcase its evolution to a carrier enablement platform powering enterprise-grade FWA at Mobile World Congress 2026, in the MediaTek booth (Hall 3, Booth 3D10). “The future of enterprise FWA is not single-network, it is intelligently orchestrated multi-network connectivity,” said Eric Plam, chief revenue officer at SIMO. “By combining AI-driven local network selection with centralized global control, carriers can deliver resilient connectivity at scale while unlocking recurring managed service revenue.” Through SIMO xSIM orchestration operating at both the device firmware layer and the cloud, SIMO enables intelligent multi-network selection,

Venture Global Announces LNG Purchase Agreement with Trafigura2.3.2026 12:02:00 CET | Press release

New 5-year agreement offers flexibility and diversification to LNG portfolio Today, Venture Global, Inc. (NYSE: VG) and Trafigura announced the execution of a new, binding agreement for the purchase of approximately 0.5 million tonnes per annum (MTPA) of U.S. liquefied natural gas (LNG) from Venture Global for five years commencing in 2026. This mid-term agreement offers greater flexibility to customers in the global LNG market and provides greater diversification for Venture Global’s LNG portfolio. “Trafigura is a global leader in LNG trading, and we are pleased to execute this mid-term LNG supply agreement with them to provide the market with flexible and reliable U.S. LNG,” said Venture Global CEO Mike Sabel. “Global energy demand is stronger than ever, and this is an important step in executing our strategy of adding more mid-term agreements, which will diversify the tenor of our LNG portfolio. Venture Global looks forward to helping ensure the world remains well-supplied in the sh

“AI Realized Through Display” … Samsung Display Showcases AI-Optimized OLED Technologies at MWC262.3.2026 10:58:00 CET | Press release

Introducing “Flex Magic Pixel™,” a panel-integrated privacy technology enabled by low-power, high-brightness LEAD™… Essential smartphone privacy for the AI era’s surge in personalized data usage “Thinner and tougher”… Foldable OLED durability proven with a golf putting challenge “Create your own K-pop concert”… MR experience equipped with 5,000 PPI RGB OLEDoS draws major attention New concept “edge devices” incorporating Samsung Display OLED’s unique free-form, low-power and high-resolution technologies unveiled – including the companion robot concept “Mini PetBot” and the interior décor item “AI Toy House” Spain’s Park Güell tile mosaics recreated through displays using 6.8-inch OLED and 27-inch QD-OLED, highlighting high color reproduction and bezel-less technology Eric Kim, Executive Vice President and Head of Mobile Strategic Marketing: “In the AI era, displays will evolve from simple viewing screens into intelligent interfaces that understand and respond to users and their surroun

Medimaps Group and Radiobotics Announce Strategic Merger to Expand AI-Driven Musculoskeletal Imaging Portfolio2.3.2026 09:00:00 CET | Press release

Radiobotics to join Medimaps Group, creating a global provider of AI-driven musculoskeletal (MSK) medical imaging software The transaction is expected to close following receipt of Danish foreign direct investment (FDI) approval and other customary closing conditions Together, they will bridge the gap between preventative bone health and acute trauma diagnostics, offering an expanded portfolio across X-ray and DXA: Fracture detection, opportunistic bone fragility assessment, and fracture risk prediction The combined entity will have a commercial reach in 90 countries through a robust network of direct and partner channels Both organizations will maintain their established brands, supported by close R&D and commercial collaboration Medimaps Group S.A., a global leader in AI-driven bone microarchitecture imaging solutions, and Radiobotics ApS, a leader in AI-powered MSK radiology solutions, today announced that they have entered into a strategic merger agreement. Closing of the transacti

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye