CA-FORESCOUT
6.12.2023 07:02:34 CET | Business Wire | Press release
Forescout, a global cybersecurity leader, today released “SIERRA:21 – Living on the Edge,” an analysis of 21 newly discovered vulnerabilities within OT/IoT routers and open-source software components. The report — produced by Forescout Research – Vedere Labs, a leading global team dedicated to uncovering vulnerabilities in critical infrastructure — emphasizes the continued risk to critical infrastructure and sheds light on possible mitigations.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231205915662/en/
Sierra:21 Infographic (Source: Forescout)
“SIERRA:21 – Living on the Edge” features research into Sierra Wireless AirLink cellular routers and some of its open-source components, such as TinyXML and OpenNDS. Sierra Wireless routers are popular — an open database of Wi-Fi networks shows 245,000 networks worldwide running Sierra Wireless for a variety of applications. For example, Sierra Wireless routers are used for police vehicles connecting to a central network management system or to stream surveillance video, in manufacturing plants for industrial asset monitoring, in healthcare facilities providing temporary connectivity and to manage electric vehicle charging stations. The 21 new vulnerabilities have the potential to stop vital communications that could impact everyday life.
Read the blog: Forescout Vedere Labs discloses 21 new vulnerabilities affecting OT/IoT routers
Forescout Research further finds:
- The attack surface is expansive with 86,000 vulnerable routers still exposed online. Less than 10% of these routers are confirmed to be patched against known previous vulnerabilities found since 2019.
-
Regions with the highest number of exposed devices includes:
- 68,605 devices in The United States
- 5,580 devices in Canada
- 3,853 devices in Australia
- 2,329 devices in France
- 1,001 devices in Thailand
- Among the 21 vulnerabilities, one has critical severity (CVSS score 9.6), nine have high severity and 11 have medium severity. These vulnerabilities allow attackers to steal credentials, take control of a router by injecting malicious code, persist on the device and use it as an initial access point into critical networks.
- Patching can’t fix everything. 90 percent of devices exposing a specific management interface have reached end of life, meaning they cannot be further patched.
- It’s an uphill battle to secure supply chain components. Open-source software elements continue to go unchecked and increase the attack surface of critical devices, leading to vulnerabilities that may be hard for organizations to track and mitigate.
“We are raising the alarm today because there remain thousands of OT/IoT devices representing an increased attack surface that requires attention,” advises Elisa Constante, VP of Research, Forescout Research – Vedere Labs. “Vulnerabilities impacting critical infrastructure are like an open window for bad actors in every community. State-sponsored actors are developing custom malware to use routers for persistence and espionage. Cybercriminals are also leveraging routers and related infrastructure for residential proxies and to recruit into botnets. Our discoveries reaffirm the need for heightened awareness of the OT/IoT edge devices that are so often neglected.”
Sierra Wireless and OpenDNS have issued patches for the identified vulnerabilities. TinyXML is an abandoned open source project, so the upstream vulnerabilities will not be fixed and must be addressed downstream.
For more information, download the full report, “SIERRA:21 – Living on the Edge,” now at https://www.forescout.com/resources/sierra21-vulnerabilities.
Additional Resources:
- View the on-demand webinar: https://www.brighttalk.com/central/account/616385/channel/13809/video/602171
- Read more insight from Forescout Research: Hacktivists attack U.S. water treatment plant – analysis and implications
About Forescout
Forescout Technologies, Inc., a global cybersecurity leader, continuously identifies, protects and helps ensure the compliance of all managed and unmanaged connected cyber assets – IT, IoT, IoMT and OT. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide vendor-agnostic, automated cybersecurity at scale. The Forescout® Platform delivers comprehensive capabilities for network security, risk and exposure management, and extended detection and response. With seamless context sharing and workflow orchestration via ecosystem partners, it enables customers to more effectively manage cyber risk and mitigate threats.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20231205915662/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Charlotte Tilbury awarded CBE in the King’s Birthday Honours 202612.6.2026 23:31:00 CEST | Press release
Charlotte Tilbury CBE, sole Founder, President, Chairman and Chief Creative Officer of Charlotte Tilbury Beauty, has been awarded a Commander of the Order of the British Empire (CBE) in the King’s Birthday Honours 2026 for services to the beauty and cosmetics industry. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260612679101/en/ Charlotte Tilbury, founder, president, chairman and chief creative officer of Charlotte Tilbury Beauty, who has been awarded a CBE (Commander of the Order of the British Empire) in 2026 for services to the beauty industry and entrepreneurship. (Photo: Charlotte Tilbury team) This honour recognises Charlotte’s contribution to leading and building Britain’s most successful global beauty brand. She has played a defining role in revolutionising the beauty industry and driving economic growth of the UK beauty sector, which has expanded from approximately £17bn in 2013 to over £31bn today. Charlotte Til
IQM Appoints Barbara Venneman, Vanguard Board Director and Former Global Head of Deloitte Digital, to its Board of Directors12.6.2026 18:36:00 CEST | Press release
Venneman brings more than 30 years of digital transformation, AI, and enterprise technology experience as IQM prepares for its planned Nasdaq listing IQM Quantum Computers, the global leader in superconducting quantum computers, today announced the appointment of Barbara Venneman to its Board of Directors. Venneman deepens the Board's expertise in digital transformation, enterprise technology commercialization, and global business scaling as IQM expands its commercial footprint worldwide. Additionally, CEO and Co-founder Jan Goetz will replace Co-founder Juha Vartiainen as the Founder representative on the IQM Board. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260612650938/en/ IQM Appoints Barbara Venneman, Vanguard Board Director and Former Global Head of Deloitte Digital, to its Board of Directors Ms. Venneman joins the IQM Board of Directors following a distinguished career at the intersection of advanced technology, s
DEWA Organises Second Agentic AI Retreat at Al Shera’a, World’s Tallest, Largest and Smartest Net‑Positive Government Building12.6.2026 17:08:00 CEST | Press release
HE Saeed Mohammed Al Tayer, MD & CEO of Dubai Electricity and Water Authority (DEWA),has emphasised that DEWA deploys the latest Agentic AI technologies, in line with the vision to enhance its leading role and reinforce Dubai’s position as the city of the future. He made these remarks during the Agentic AI Executive Retreat DEWA organised at Al Shera’a, its new headquarters, which is the world’s tallest, largest and smartest net-positive government building. The event was attended by the executive leadership team and key stakeholders in digital transformation and artificial intelligence (AI), as well as representatives from SAP and McKinsey. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260612633834/en/ DEWA organises second Agentic AI Retreat at Al Shera’a, world’s tallest, largest and smartest net positive government building (Photo: AETOSWire) In his speech, Al Tayer said that DEWA is guided by directives from the wise l
BeOne Medicines’ Foundational Hematology Franchise Leads Next Era of B-Cell Cancer Innovation at EHA 202612.6.2026 12:00:00 CEST | Press release
Tacabrutideg (BGB-16673, BTK degrader) showed durable responses in heavily pretreated R/R CLL and BTK inhibitor–naïve patients, signaling potential for earlier lines of treatmentBRUKINSA plus sonrotoclax (ZS) delivered deep, durable responses and high uMRD rates across TN CLL and R/R MCL and CLL, reinforcing its potential as an all-oral, fixed-duration treatment BeOne Medicines Ltd. (Nasdaq: ONC; HKEX: 06160; SSE: 688235), a global oncology company, today announced new data from its foundational hematology franchise at the 2026 European Hematology Association (EHA) Congress in Stockholm. Updated results from tacabrutideg (BGB-16673), a potential best-in-class Bruton’s tyrosine kinase (BTK) degrader, demonstrated durable responses in pretreated relapsed/refractory (R/R) chronic lymphocytic leukemia/small lymphocytic lymphoma (CLL/SLL), with early activity also seen in BTK inhibitor–naïve patients. These data are complemented by results from the all-oral combination of BRUKINSA® (zanubru
Cyviz: Microsoft’s Immersive Approach to Collaboration12.6.2026 09:00:00 CEST | Press release
At Microsoft’s Innovation Hub in Amsterdam, immersive technology is used to enable co-creation rather than one-way presentations. In the company’s Immersive Suite, customers, data experts, and technology specialists come together in a shared environment to address complex challenges more effectively. Watch Video Case Study >> This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260612831180/en/ Watch Video Case Study >> https://www.cyviz.com/case-studies/microsoft-immersive-suite/ As business and technology environments grow more complex, establishing shared understanding across disciplines has become critical. The Immersive Suite is designed for active collaboration, where visual narratives, data, and technical content are explored interactively. This allows participants to test scenarios, align perspectives, and move more efficiently from discussion to decision. “We deliberately work with familiar tools like PowerPoint. That all
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
