CA-FORESCOUT
6.12.2023 07:02:34 CET | Business Wire | Press release
Forescout, a global cybersecurity leader, today released “SIERRA:21 – Living on the Edge,” an analysis of 21 newly discovered vulnerabilities within OT/IoT routers and open-source software components. The report — produced by Forescout Research – Vedere Labs, a leading global team dedicated to uncovering vulnerabilities in critical infrastructure — emphasizes the continued risk to critical infrastructure and sheds light on possible mitigations.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231205915662/en/
Sierra:21 Infographic (Source: Forescout)
“SIERRA:21 – Living on the Edge” features research into Sierra Wireless AirLink cellular routers and some of its open-source components, such as TinyXML and OpenNDS. Sierra Wireless routers are popular — an open database of Wi-Fi networks shows 245,000 networks worldwide running Sierra Wireless for a variety of applications. For example, Sierra Wireless routers are used for police vehicles connecting to a central network management system or to stream surveillance video, in manufacturing plants for industrial asset monitoring, in healthcare facilities providing temporary connectivity and to manage electric vehicle charging stations. The 21 new vulnerabilities have the potential to stop vital communications that could impact everyday life.
Read the blog: Forescout Vedere Labs discloses 21 new vulnerabilities affecting OT/IoT routers
Forescout Research further finds:
- The attack surface is expansive with 86,000 vulnerable routers still exposed online. Less than 10% of these routers are confirmed to be patched against known previous vulnerabilities found since 2019.
-
Regions with the highest number of exposed devices includes:
- 68,605 devices in The United States
- 5,580 devices in Canada
- 3,853 devices in Australia
- 2,329 devices in France
- 1,001 devices in Thailand
- Among the 21 vulnerabilities, one has critical severity (CVSS score 9.6), nine have high severity and 11 have medium severity. These vulnerabilities allow attackers to steal credentials, take control of a router by injecting malicious code, persist on the device and use it as an initial access point into critical networks.
- Patching can’t fix everything. 90 percent of devices exposing a specific management interface have reached end of life, meaning they cannot be further patched.
- It’s an uphill battle to secure supply chain components. Open-source software elements continue to go unchecked and increase the attack surface of critical devices, leading to vulnerabilities that may be hard for organizations to track and mitigate.
“We are raising the alarm today because there remain thousands of OT/IoT devices representing an increased attack surface that requires attention,” advises Elisa Constante, VP of Research, Forescout Research – Vedere Labs. “Vulnerabilities impacting critical infrastructure are like an open window for bad actors in every community. State-sponsored actors are developing custom malware to use routers for persistence and espionage. Cybercriminals are also leveraging routers and related infrastructure for residential proxies and to recruit into botnets. Our discoveries reaffirm the need for heightened awareness of the OT/IoT edge devices that are so often neglected.”
Sierra Wireless and OpenDNS have issued patches for the identified vulnerabilities. TinyXML is an abandoned open source project, so the upstream vulnerabilities will not be fixed and must be addressed downstream.
For more information, download the full report, “SIERRA:21 – Living on the Edge,” now at https://www.forescout.com/resources/sierra21-vulnerabilities.
Additional Resources:
- View the on-demand webinar: https://www.brighttalk.com/central/account/616385/channel/13809/video/602171
- Read more insight from Forescout Research: Hacktivists attack U.S. water treatment plant – analysis and implications
About Forescout
Forescout Technologies, Inc., a global cybersecurity leader, continuously identifies, protects and helps ensure the compliance of all managed and unmanaged connected cyber assets – IT, IoT, IoMT and OT. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide vendor-agnostic, automated cybersecurity at scale. The Forescout® Platform delivers comprehensive capabilities for network security, risk and exposure management, and extended detection and response. With seamless context sharing and workflow orchestration via ecosystem partners, it enables customers to more effectively manage cyber risk and mitigate threats.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20231205915662/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Datang Mobile, KPN, NEC and Wilus are Latest Licensors to Join Sisvel POS Patent Pool as Incentive Deadline Nears5.5.2026 10:02:00 CEST | Press release
Datang Mobile, KPN, NEC and Wilus have become the latest licensors in the Sisvel point of sale (POS) patent pool. They join seven other patent owners in making their 2G-5G cellular portfolios available through the programme: BlackBerry, Huawei, JVCKENWOOD, LG Electronics, Nokia, Sisvel and SK Telecom. The period for Sisvel POS licensors to benefit from early participation incentives is set to close on 15 May. Cellular patent owners interested in becoming involved should contact Sisvel as soon as possible. The pool, which is the first in the market to address the POS vertical, was announced at the beginning of April, with Huawei, LG Electronics and Nokia as founding licensors. “We have received a great response from the market so far, and I am pleased to welcome Datang, KPN, NEC and Wilus as the latest licensors,” says POS programme manager Sven Törringer. “We have put together a formidable group of cellular technology innovators, and there are many more companies in the pipeline. I am
Bregal Milestone Announces Majority Growth Investment in meteoviva, an AI-Powered Building Energy Management Solution5.5.2026 10:01:00 CEST | Press release
Partnership to scale one of Europe's largest autonomous energy management solutions amid accelerating decarbonisation mandates and rising AI adoption in commercial real estate Bregal Milestone, a leading European software growth private equity firm, today announced a majority growth investment in meteoviva GmbH (“meteoviva” or the “Company”), a pioneer in AI-powered predictive building energy management. meteoviva's intelligent solutions combine a proprietary physics-based thermodynamic model with AI to deliver energy cost reductions of up to 45 percent across large-scale commercial real estate portfolios, without structural retrofits. meteoviva is widely recognised as a market leader in autonomous building energy management, with over 500 buildings across 19 countries, accounting for 11.5 million square metres of real estate under active control. Its customer base includes some of Europe's most demanding buildings, among them Germany's largest office building, The Squaire at Frankfurt
Schindler Selects Navan to Elevate Global Travel Operations5.5.2026 10:00:00 CEST | Press release
Leading provider of sustainable and smart urban mobility deploys Navan to deliver a seamless experience for its workforce Navan (NASDAQ: NAVN), the global AI-powered business travel and expense management platform, today announced it has been selected by Schindler, the leading provider of sustainable and smart urban mobility, to modernize its global travel program. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260505725595/en/ Leading provider of sustainable and smart urban mobility deploys Navan to deliver a seamless experience for its workforce With over 150 years of industry innovation, Schindler has reshaped mobility in urban societies, growing from a local manufacturer into a global elevator, escalators and moving walkways business. To support its next phase of growth, the company has chosen to consolidate its travel operations – moving away from a fragmented online booking model. By deploying Navan, Schindler is now u
OCTO and Sedgwick Announce Strategic Telematics Partnership5.5.2026 10:00:00 CEST | Press release
OCTO, a global leader in telematics and data analytics, today announced a strategic partnership with Sedgwick, the world’s leading provider of claims and risk management solutions. Together, the two companies will reshape the future of insurance and mobility by combining advanced telematics with claims management services. The collaboration aims to create a new model where telematics and efficiency come together to transform the customer experience. By integrating OCTO’s cutting-edge telematics insights with Sedgwick’s global expertise in claims handling, the partnership will unlock a series of tangible benefits: enhanced speed and accuracy in crash and claims intake, quicker and more consistent liability assessments, fraud validation and reduction, optimized alerts to improve driver safety, and significant reductions in the overall cost and lifecycle of claims. The joint solution is telematics-agnostic, able to ingest data from connected cars, fleet management systems, or OCTO’s own o
SWISSto12 Partners With German Consortium HPS/LSS on First-Ever Unfurling Antenna Reflector to Be Built in Europe for Commercial GEO Telecommunications Satellite5.5.2026 09:00:00 CEST | Press release
Latest contract awarded signals strong momentum in SWISSto12’s strategy to strengthen European capabilities to build end-to-end space systems SWISSto12 announced today a major contract with German high-performance space subsystem providersHPS/LSS. The Munich-based consortium will provide a large deployable reflector subsystem (LDRS) for the NEASTAR-1 mission, built on HummingSat, enabling the world’s first direct-to-device media broadcasting capabilities from geostationary orbit. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260505082353/en/ SWISSto12 enables world-first approach to GEO-based D2D connectivity, leveraging an unfurling antenna, in collaboration with HPS/LSS The German-led antenna reflector subsystem is the result of more than 15 years of development under the European Space Agency’s (ESA) Advanced Research in Telecommunications (ARTES) programme, ESA’s Earth Observation Technology Development activities, and
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
