CA-FORESCOUT
6.12.2023 07:02:34 CET | Business Wire | Press release
Forescout, a global cybersecurity leader, today released “SIERRA:21 – Living on the Edge,” an analysis of 21 newly discovered vulnerabilities within OT/IoT routers and open-source software components. The report — produced by Forescout Research – Vedere Labs, a leading global team dedicated to uncovering vulnerabilities in critical infrastructure — emphasizes the continued risk to critical infrastructure and sheds light on possible mitigations.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231205915662/en/
Sierra:21 Infographic (Source: Forescout)
“SIERRA:21 – Living on the Edge” features research into Sierra Wireless AirLink cellular routers and some of its open-source components, such as TinyXML and OpenNDS. Sierra Wireless routers are popular — an open database of Wi-Fi networks shows 245,000 networks worldwide running Sierra Wireless for a variety of applications. For example, Sierra Wireless routers are used for police vehicles connecting to a central network management system or to stream surveillance video, in manufacturing plants for industrial asset monitoring, in healthcare facilities providing temporary connectivity and to manage electric vehicle charging stations. The 21 new vulnerabilities have the potential to stop vital communications that could impact everyday life.
Read the blog: Forescout Vedere Labs discloses 21 new vulnerabilities affecting OT/IoT routers
Forescout Research further finds:
- The attack surface is expansive with 86,000 vulnerable routers still exposed online. Less than 10% of these routers are confirmed to be patched against known previous vulnerabilities found since 2019.
-
Regions with the highest number of exposed devices includes:
- 68,605 devices in The United States
- 5,580 devices in Canada
- 3,853 devices in Australia
- 2,329 devices in France
- 1,001 devices in Thailand
- Among the 21 vulnerabilities, one has critical severity (CVSS score 9.6), nine have high severity and 11 have medium severity. These vulnerabilities allow attackers to steal credentials, take control of a router by injecting malicious code, persist on the device and use it as an initial access point into critical networks.
- Patching can’t fix everything. 90 percent of devices exposing a specific management interface have reached end of life, meaning they cannot be further patched.
- It’s an uphill battle to secure supply chain components. Open-source software elements continue to go unchecked and increase the attack surface of critical devices, leading to vulnerabilities that may be hard for organizations to track and mitigate.
“We are raising the alarm today because there remain thousands of OT/IoT devices representing an increased attack surface that requires attention,” advises Elisa Constante, VP of Research, Forescout Research – Vedere Labs. “Vulnerabilities impacting critical infrastructure are like an open window for bad actors in every community. State-sponsored actors are developing custom malware to use routers for persistence and espionage. Cybercriminals are also leveraging routers and related infrastructure for residential proxies and to recruit into botnets. Our discoveries reaffirm the need for heightened awareness of the OT/IoT edge devices that are so often neglected.”
Sierra Wireless and OpenDNS have issued patches for the identified vulnerabilities. TinyXML is an abandoned open source project, so the upstream vulnerabilities will not be fixed and must be addressed downstream.
For more information, download the full report, “SIERRA:21 – Living on the Edge,” now at https://www.forescout.com/resources/sierra21-vulnerabilities.
Additional Resources:
- View the on-demand webinar: https://www.brighttalk.com/central/account/616385/channel/13809/video/602171
- Read more insight from Forescout Research: Hacktivists attack U.S. water treatment plant – analysis and implications
About Forescout
Forescout Technologies, Inc., a global cybersecurity leader, continuously identifies, protects and helps ensure the compliance of all managed and unmanaged connected cyber assets – IT, IoT, IoMT and OT. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide vendor-agnostic, automated cybersecurity at scale. The Forescout® Platform delivers comprehensive capabilities for network security, risk and exposure management, and extended detection and response. With seamless context sharing and workflow orchestration via ecosystem partners, it enables customers to more effectively manage cyber risk and mitigate threats.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20231205915662/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Miro Announces Asia Hub in Singapore to Accelerate Growth Across the Region and Bring AI Collaboration to New Markets17.3.2026 02:00:00 CET | Press release
AI Innovation Workspace perfectly placed to help organisations maximise AI investment and accelerate innovation Miro®, the AI Innovation Workspace for teams, today announced plans to expand its operations in Asia, supporting organisations across the region in their AI transformation journey. Miro is investing in people, resources, and infrastructure as it targets growth in key markets, including Singapore, India, South Korea, and other Southeast Asia countries. As the global innovation centre of gravity shifts toward Asia – where R&D spending reached 45% of global investment in 2024 – the organisations leading this charge need tools and platforms built for the complexity and pace of modern innovation and collaboration. Miro's AI-powered innovation workspace is uniquely positioned to support this moment. Miro gives organisations the shared context layer they need to move from insight to execution faster than ever before. For Asia's most ambitious innovators, where speed-to-market and cr
IQM and Zurich Instruments Launch Real-Time Quantum Error Correction Demonstrator with NVIDIA NVQLink16.3.2026 22:24:00 CET | Press release
The demonstrator being built in this project delivers a clear path toward scalable and fault-tolerant quantum computers. The joint project integrates IQM’s superconducting quantum processor, Zurich Instruments’ ZQCS Quantum Control System, with the NVIDIA NVQLink platform to enable real-time error correction. This initiative establishes a foundation for standardized enterprise-ready quantum systems, and datacenter deployment. Today, IQM Quantum Computers and Zurich Instruments announce a joint project to build and operate a real-time quantum error correction (QEC) demonstrator, enabled by the NVIDIA NVQLink platform. This project marks a significant milestone toward scalable and fault-tolerant quantum computing designed for enterprise and datacenter deployment. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260316511715/en/ IQM and Zurich Instruments launch real-time quantum error correction demonstrator with NVIDIA NVQLink
Kinaxis Advances Large-Scale Supply Chain Optimization with NVIDIA AI16.3.2026 21:30:00 CET | Press release
Achieves up to 12X faster end-to-end planning performance in large-scale enterprise models Kinaxis® Inc. (TSX: KXS), a global leader in supply chain orchestration, today announced a new milestone in advancing large-scale supply chain optimization within the Kinaxis Maestro™ platform. Maestro already delivers high-performance optimization across complex global supply chains, and Kinaxis is now extending that leadership by leveraging GPU acceleration powered by NVIDIA cuOpt™ and NVIDIA AI infrastructure. As supply chains grow in scale and complexity, planning models must reconcile tens of millions of variables across extended time horizons and multiple planning levels. As model size expands, the number of potential decisions can scale into billions, dramatically increasing computational needs. Organizations are no longer constrained by insight alone. They are constrained by how quickly they can iterate. In testing on a large-scale semiconductor planning model with nearly 50 million decis
Lattice Joins NVIDIA Halos Ecosystem to Advance Safety for Physical AI with Holoscan Sensor Bridge16.3.2026 21:30:00 CET | Press release
Lattice Semiconductor (NASDAQ: LSCC), the low power programmable leader, today announced it has joined the NVIDIA Halos AI Systems Inspection Lab ecosystem, the first ANSI National Accreditation Board (ANAB) accredited inspection lab for AI-driven physical systems. Announced at the NVIDIA GTC 2026, Lattice will engage with NVIDIA and other Halos ecosystem members to build Halos-certified Holoscan Sensor Bridge-based designs for physical AI and to help shape best practices as the industry evolves. “Physical AI is rapidly moving from controlled environments into the real world, where safety, reliability, and trust are paramount,” said Raemin Wang, Vice President, Segment Marketing, Lattice Semiconductor. “Through this collaboration, Lattice looks forward to contributing our expertise in low power FPGAs and award-winning solution stacks to enable scalable, trusted physical AI systems across robotics, industrial automation, and autonomous applications.” NVIDIA Halos is a comprehensive full
Lenovo Brings Production-Scale AI to Global Sports: Enhancing Fan Experience, Driving Revenue Growth, Boosting Performance, and Improving Operational Efficiency with NVIDIA16.3.2026 21:30:00 CET | Press release
Multiyear collaboration introduces new solutions spanning Sports Intelligence, Operations, and Media & Content. At NVIDIA GTC today, Lenovo (HKSE: 992) (ADR: LNVGY) announced an expanded multiyear collaboration with NVIDIA to help the global sports industry deploy production-scale AI across mission-critical environments, transforming live data into revenue growth, operational resilience, and real-time decision advantage. The global sports technology market is projected to grow from $23 billion in 2025 to more than $60 billion by 2030. Global sports events represent some of the most complex and demanding operating environments in any industry, combining unprecedented scale, technical sophistication, and public visibility. These events engage billions of viewers worldwide, generate and process petabytes of data in real time, and require highly coordinated, distributed operations across multiple countries, all within a context where reliability, resilience, and uninterrupted performance a
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
