CA-FORESCOUT
6.12.2023 07:02:34 CET | Business Wire | Press release
Forescout, a global cybersecurity leader, today released “SIERRA:21 – Living on the Edge,” an analysis of 21 newly discovered vulnerabilities within OT/IoT routers and open-source software components. The report — produced by Forescout Research – Vedere Labs, a leading global team dedicated to uncovering vulnerabilities in critical infrastructure — emphasizes the continued risk to critical infrastructure and sheds light on possible mitigations.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231205915662/en/
Sierra:21 Infographic (Source: Forescout)
“SIERRA:21 – Living on the Edge” features research into Sierra Wireless AirLink cellular routers and some of its open-source components, such as TinyXML and OpenNDS. Sierra Wireless routers are popular — an open database of Wi-Fi networks shows 245,000 networks worldwide running Sierra Wireless for a variety of applications. For example, Sierra Wireless routers are used for police vehicles connecting to a central network management system or to stream surveillance video, in manufacturing plants for industrial asset monitoring, in healthcare facilities providing temporary connectivity and to manage electric vehicle charging stations. The 21 new vulnerabilities have the potential to stop vital communications that could impact everyday life.
Read the blog: Forescout Vedere Labs discloses 21 new vulnerabilities affecting OT/IoT routers
Forescout Research further finds:
- The attack surface is expansive with 86,000 vulnerable routers still exposed online. Less than 10% of these routers are confirmed to be patched against known previous vulnerabilities found since 2019.
-
Regions with the highest number of exposed devices includes:
- 68,605 devices in The United States
- 5,580 devices in Canada
- 3,853 devices in Australia
- 2,329 devices in France
- 1,001 devices in Thailand
- Among the 21 vulnerabilities, one has critical severity (CVSS score 9.6), nine have high severity and 11 have medium severity. These vulnerabilities allow attackers to steal credentials, take control of a router by injecting malicious code, persist on the device and use it as an initial access point into critical networks.
- Patching can’t fix everything. 90 percent of devices exposing a specific management interface have reached end of life, meaning they cannot be further patched.
- It’s an uphill battle to secure supply chain components. Open-source software elements continue to go unchecked and increase the attack surface of critical devices, leading to vulnerabilities that may be hard for organizations to track and mitigate.
“We are raising the alarm today because there remain thousands of OT/IoT devices representing an increased attack surface that requires attention,” advises Elisa Constante, VP of Research, Forescout Research – Vedere Labs. “Vulnerabilities impacting critical infrastructure are like an open window for bad actors in every community. State-sponsored actors are developing custom malware to use routers for persistence and espionage. Cybercriminals are also leveraging routers and related infrastructure for residential proxies and to recruit into botnets. Our discoveries reaffirm the need for heightened awareness of the OT/IoT edge devices that are so often neglected.”
Sierra Wireless and OpenDNS have issued patches for the identified vulnerabilities. TinyXML is an abandoned open source project, so the upstream vulnerabilities will not be fixed and must be addressed downstream.
For more information, download the full report, “SIERRA:21 – Living on the Edge,” now at https://www.forescout.com/resources/sierra21-vulnerabilities.
Additional Resources:
- View the on-demand webinar: https://www.brighttalk.com/central/account/616385/channel/13809/video/602171
- Read more insight from Forescout Research: Hacktivists attack U.S. water treatment plant – analysis and implications
About Forescout
Forescout Technologies, Inc., a global cybersecurity leader, continuously identifies, protects and helps ensure the compliance of all managed and unmanaged connected cyber assets – IT, IoT, IoMT and OT. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide vendor-agnostic, automated cybersecurity at scale. The Forescout® Platform delivers comprehensive capabilities for network security, risk and exposure management, and extended detection and response. With seamless context sharing and workflow orchestration via ecosystem partners, it enables customers to more effectively manage cyber risk and mitigate threats.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20231205915662/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Cleaner by Design: SaniSure Introduces PETG PharmaTainer™ Ultra-Clean Bottles & Carboys20.4.2026 16:00:00 CEST | Press release
Industry’s most widely adopted PETG material meets industry-leading cleanliness, compliance, and RNase/DNase-free validation—now available across the full bioprocessing workflow. SaniSure® today announced the launch of PETG PharmaTainer™, a new line of bioprocessing bottles and carboys combining widely accepted, medical-grade Eastman Eastar® PETG 6763 resin (DMF#9987) with SaniSure’s proprietary process and advanced automation. This launch expands SaniSure’s established PharmaTainer® platform—extending its proven cleanliness, robustness, and performance attributes to include industry-standard PETG alongside its existing PET and PC offerings. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260420641769/en/ PETG PharmaTainer™ bottles and carboys—RNase/DNase-free, ultra-clean, ready-to-use containers for bioprocessing applications. Available in volumes from 10 mL stability vials to 10 L carboys — in sterile (gamma-irradiated) an
Leaders of Dubai-Based Unicorns Hail City as Global Innovation Hub Shaping Future Technology and Driving the Digital Economy20.4.2026 15:08:00 CEST | Press release
Leaders of Dubai-based unicorn companies have reaffirmed the emirate’s status as a global hub for digital innovation and technology-led growth. The senior executives highlighted Dubai’s forward-looking regulatory environment, advanced infrastructure, and ability to attract international talent as key factors strengthening its appeal for high-growth digital businesses. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260420503062/en/ Leaders of Dubai-based unicorns hail city as global innovation hub shaping future technology and driving the digital economy (Photo: AETOSWire) They noted that Dubai has evolved into a strategic launchpad for ambitious companies, offering an agile business environment that supports innovation and enables expansion into regional and international markets. The business leaders also praised the strong alignment between the public and private sectors within Dubai’s digital ecosystem, supported by Dubai
Capcom’s All-New IP PRAGMATA Surpasses One Million Units Sold in Two Days!20.4.2026 15:00:00 CEST | Press release
– Highly innovative and original gameplay earns strong reception from players around the globe – Capcom Co., Ltd. (TOKYO:9697) today announced that worldwide sales of PRAGMATA, the company’s all-new IP released on April 17, 2026*, have surpassed one million units. PRAGMATA is a science-fiction action-adventure game that depicts the journey of Hugh Williams and Diana, an android girl, in a near-future lunar world. A completely new IP, PRAGMATA was developed primarily by a team of younger Capcom developers, who created an innovative gameplay experience by fusing action gameplay with puzzle elements set within a distinctive world ruled over by artificial intelligence. In the absence of an established fan base or preexisting brand recognition, Capcom implemented a range of marketing initiatives—beginning with the early release of a playable demo—to communicate the unique features of the game to a wider audience. In addition, in line with the company’s multi-platform strategy, Capcom broade
Following Oral Presentation of Phase I Data at AACR 2026, Debiopharm Announces FDA Fast Track Designation for Lunresertib in Combination With Zedoresertib for Genomic-Defined Platinum-Resistant Ovarian Cancer20.4.2026 14:30:00 CEST | Press release
Debiopharm (www.debiopharm.com), a privately-owned, Swiss-based biopharmaceutical company aiming to establish tomorrow’s standard of care to cure cancer and infectious diseases, today announced that the U.S. Food and Drug Administration (FDA) has granted Fast Track designation to the combination of its PKMYT1 inhibitor, lunresertib (Debio2513), and its WEE1 inhibitor, zedoresertib (Debio 0123). The designation is for the treatment of adult patients with CCNE1 amplified, or a deleterious mutation in either FBXW7 or PPP2R1A, platinum-resistant/refractory ovarian cancer. The FDA’s Fast Track program is designed to facilitate the development and expedite the review of new drugs intended to treat serious conditions and fill an unmet medical need. Programs granted Fast Track designation benefit from more frequent communication with the FDA and, if relevant criteria are met, may be eligible for Priority Review and Accelerated Approval of a New Drug Application (NDA). Momentum Following AACR O
Data4Industry-X Empowers Industrial Organizations in Meeting Digital Product Passport Requirements20.4.2026 14:17:00 CEST | Press release
Contributing to the International Manufacturing-X Council Showcase at Hannover Messe, to improve resilience, productivity and innovation in Manufacturing Hannover Messe - Data4Industry-X, the trusted industry data space solution, builds its momentum by accelerating Digital Product Passport (DPP) compliance with trusted, secure and traceable data exchange at scale, as demonstrated at Hannover Messe April 20-24, 2026 . As theDigital Product Passport becomes a regulatory reality for manufacturing organizations, the ability to exchange data in a trusted, secure and traceable environment across the entire supply chain, in compliance with data regulations such as the Data Act, has become critical. Actively contributing to the International Manufacturing-X Council showcase, driven by LNI 4.0 association involving 16 countries, Data4Industry-X, a decentralized environment, demonstrates the use case of the DPP on the battery’s State of Health, and how the battery current capacity and performanc
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
