CA-FORESCOUT
Forescout, a global cybersecurity leader, today released “SIERRA:21 – Living on the Edge,” an analysis of 21 newly discovered vulnerabilities within OT/IoT routers and open-source software components. The report — produced by Forescout Research – Vedere Labs, a leading global team dedicated to uncovering vulnerabilities in critical infrastructure — emphasizes the continued risk to critical infrastructure and sheds light on possible mitigations.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231205915662/en/
Sierra:21 Infographic (Source: Forescout)
“SIERRA:21 – Living on the Edge” features research into Sierra Wireless AirLink cellular routers and some of its open-source components, such as TinyXML and OpenNDS. Sierra Wireless routers are popular — an open database of Wi-Fi networks shows 245,000 networks worldwide running Sierra Wireless for a variety of applications. For example, Sierra Wireless routers are used for police vehicles connecting to a central network management system or to stream surveillance video, in manufacturing plants for industrial asset monitoring, in healthcare facilities providing temporary connectivity and to manage electric vehicle charging stations. The 21 new vulnerabilities have the potential to stop vital communications that could impact everyday life.
Read the blog: Forescout Vedere Labs discloses 21 new vulnerabilities affecting OT/IoT routers
Forescout Research further finds:
- The attack surface is expansive with 86,000 vulnerable routers still exposed online. Less than 10% of these routers are confirmed to be patched against known previous vulnerabilities found since 2019.
-
Regions with the highest number of exposed devices includes:
- 68,605 devices in The United States
- 5,580 devices in Canada
- 3,853 devices in Australia
- 2,329 devices in France
- 1,001 devices in Thailand
- Among the 21 vulnerabilities, one has critical severity (CVSS score 9.6), nine have high severity and 11 have medium severity. These vulnerabilities allow attackers to steal credentials, take control of a router by injecting malicious code, persist on the device and use it as an initial access point into critical networks.
- Patching can’t fix everything. 90 percent of devices exposing a specific management interface have reached end of life, meaning they cannot be further patched.
- It’s an uphill battle to secure supply chain components. Open-source software elements continue to go unchecked and increase the attack surface of critical devices, leading to vulnerabilities that may be hard for organizations to track and mitigate.
“We are raising the alarm today because there remain thousands of OT/IoT devices representing an increased attack surface that requires attention,” advises Elisa Constante, VP of Research, Forescout Research – Vedere Labs. “Vulnerabilities impacting critical infrastructure are like an open window for bad actors in every community. State-sponsored actors are developing custom malware to use routers for persistence and espionage. Cybercriminals are also leveraging routers and related infrastructure for residential proxies and to recruit into botnets. Our discoveries reaffirm the need for heightened awareness of the OT/IoT edge devices that are so often neglected.”
Sierra Wireless and OpenDNS have issued patches for the identified vulnerabilities. TinyXML is an abandoned open source project, so the upstream vulnerabilities will not be fixed and must be addressed downstream.
For more information, download the full report, “SIERRA:21 – Living on the Edge,” now at https://www.forescout.com/resources/sierra21-vulnerabilities.
Additional Resources:
- View the on-demand webinar: https://www.brighttalk.com/central/account/616385/channel/13809/video/602171
- Read more insight from Forescout Research: Hacktivists attack U.S. water treatment plant – analysis and implications
About Forescout
Forescout Technologies, Inc., a global cybersecurity leader, continuously identifies, protects and helps ensure the compliance of all managed and unmanaged connected cyber assets – IT, IoT, IoMT and OT. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide vendor-agnostic, automated cybersecurity at scale. The Forescout® Platform delivers comprehensive capabilities for network security, risk and exposure management, and extended detection and response. With seamless context sharing and workflow orchestration via ecosystem partners, it enables customers to more effectively manage cyber risk and mitigate threats.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20231205915662/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Aesyra Demonstrates Significant Sleep Bruxism Reduction in Clinical Study26.1.2026 09:00:00 CET | Press release
Aesyra SA, a Swiss medtech company developing innovative digital therapeutics for dental and sleep-related disorders, today announced the successful completion of its clinical investigation evaluating the efficacy and safety of AesyBite™ Active, an intelligent oral appliance designed to treat and prevent sleep bruxism through biofeedback. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260126533019/en/ AesyBite Custom smart nightguard by Aesyra SA. The clinical investigation demonstrated that AesyBite™ Active achieved a statistically significant and clinically meaningful reduction in sleep bruxism activity, exceeding the predefined performance target. Strong and robust clinical outcomes In the study (Identifier: NCT06153810), involving 26 adult patients with confirmed sleep bruxism, activation of the AesyBite Active biofeedback system resulted in a 60.6% reduction in total sleep bruxism duration per hour compared to baseline
Franklin Templeton Aligns Alternative Credit Firms Under BSP Brand26.1.2026 08:58:00 CET | Press release
Benefit Street Partners and Alcentra align under a single, refreshed BSP brand.Move reflects client demand for a specialist, integrated and global credit platform.Franklin Templeton’s alternative credit platform on track to exceed $100bn in 2026.BSP outlines further growth plans including expansion in the Middle East and Asia.New research says 51% of institutional investors will increase credit allocation in 2026.81% of institutions say a specialist focus on credit is the top attribute for performance. Franklin Templeton’s US and European alternative credit businesses, Benefit Street Partners and Alcentra, have now aligned under an updated Benefit Street Partners (BSP) brand. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260123270080/en/ David Manlowe, CEO of Benefit Street Partners The move is the final step in BSP and Alcentra’s integration – two pioneering alternative credit firms that Franklin Templeton acquired in 2019
Samsung Epis Holdings Reports Fourth Quarter and Fiscal Year 2025 Financial Results26.1.2026 08:00:00 CET | Press release
In its first financial results announcement after the spin-off, Samsung Bioepis recorded FY2025 revenue of KRW 1.672 trillion, highest annual revenue in its 14-year historyExcluding milestone revenue, annual sales revenue grew 28% year-over-year (YoY), recording KRW 1.626 trillion, with 101% YoY growth in operating profit to KRW 330.8 billion Samsung Epis Holdings (KRX: 0126Z0), an investment company dedicated to innovations in biopharmaceuticals and biotechnology, today announced financial results for the fourth quarter and fiscal year 2025. “We are very pleased to report strong year-to-date sales growth in our first financial results following the spin-off. Our organic growth has been driven by solid performance across our biosimilars portfolio," said Kyung-Ah Kim, President and Chief Executive Officer (CEO) of Samsung Epis Holdings. “We are continuing to make meaningful progress in our regulatory and commercial milestones with our existing biosimilars portfolio, while strategically
Syngenta and Statkraft Sign Five-Year Virtual Power Purchase Agreement26.1.2026 08:00:00 CET | Press release
Virtual wind PPA with guarantees of origin to decarbonize Syngenta's plants in Europe Important element in carbon reduction journey for Syngenta AG Syngenta, one of the world’s biggest agricultural innovation companies, and Statkraft, a leading provider of innovative green energy solutions in Europe, have signed a virtual power purchase agreement (vPPA) covering Syngenta’s CP & Seeds operations for a period of five years. The volume amounts to 125 GWh per year and a total of 625 GWh of green electricity by the end of the contract in 2030. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260125701845/en/ Syngenta and Statkraft sign five-year virtual power purchase agreement With the vPPA, Statkraft is supporting Syngenta in advancing its sustainability strategy through the purchase of renewable energy. "This is Syngenta's first vPPA, marking a pivotal step in our decarbonization strategy," said Rachel Stenson Bugnon, Global Hea
Merz Therapeutics Submits Application to the European Medicines Agency for New Indication of XEOMIN® in Pediatric Spasticity26.1.2026 08:00:00 CET | Press release
Merz Therapeutics, a leading player in neurology-focused specialty pharma, today announced that it has completed the regulatory submission for XEOMIN® (incobotulinumtoxinA) for the treatment of spasticity of the lower and upper limb in children and adolescents aged 2–17 years in the European Union (EU) and European Economic Area (EEA). If approved, the indication would expand access to an established botulinum neurotoxin therapy for some of the youngest and most vulnerable patients across Europe. Spasticity is a common and often debilitating condition in children and adolescents with certain neurological conditions, leading to increased muscle tone that can significantly limit movement, function and independence. One of the most common underlying causes of spasticity in children is cerebral palsy (CP), the most frequent motor disability in childhood, with spastic forms accounting for approximately 80% of all cases. In more severe cases, spasticity associated with CP can also affect spe
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
