CA-FORESCOUT
Forescout, a global cybersecurity leader, today released “SIERRA:21 – Living on the Edge,” an analysis of 21 newly discovered vulnerabilities within OT/IoT routers and open-source software components. The report — produced by Forescout Research – Vedere Labs, a leading global team dedicated to uncovering vulnerabilities in critical infrastructure — emphasizes the continued risk to critical infrastructure and sheds light on possible mitigations.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231205915662/en/
Sierra:21 Infographic (Source: Forescout)
“SIERRA:21 – Living on the Edge” features research into Sierra Wireless AirLink cellular routers and some of its open-source components, such as TinyXML and OpenNDS. Sierra Wireless routers are popular — an open database of Wi-Fi networks shows 245,000 networks worldwide running Sierra Wireless for a variety of applications. For example, Sierra Wireless routers are used for police vehicles connecting to a central network management system or to stream surveillance video, in manufacturing plants for industrial asset monitoring, in healthcare facilities providing temporary connectivity and to manage electric vehicle charging stations. The 21 new vulnerabilities have the potential to stop vital communications that could impact everyday life.
Read the blog: Forescout Vedere Labs discloses 21 new vulnerabilities affecting OT/IoT routers
Forescout Research further finds:
- The attack surface is expansive with 86,000 vulnerable routers still exposed online. Less than 10% of these routers are confirmed to be patched against known previous vulnerabilities found since 2019.
-
Regions with the highest number of exposed devices includes:
- 68,605 devices in The United States
- 5,580 devices in Canada
- 3,853 devices in Australia
- 2,329 devices in France
- 1,001 devices in Thailand
- Among the 21 vulnerabilities, one has critical severity (CVSS score 9.6), nine have high severity and 11 have medium severity. These vulnerabilities allow attackers to steal credentials, take control of a router by injecting malicious code, persist on the device and use it as an initial access point into critical networks.
- Patching can’t fix everything. 90 percent of devices exposing a specific management interface have reached end of life, meaning they cannot be further patched.
- It’s an uphill battle to secure supply chain components. Open-source software elements continue to go unchecked and increase the attack surface of critical devices, leading to vulnerabilities that may be hard for organizations to track and mitigate.
“We are raising the alarm today because there remain thousands of OT/IoT devices representing an increased attack surface that requires attention,” advises Elisa Constante, VP of Research, Forescout Research – Vedere Labs. “Vulnerabilities impacting critical infrastructure are like an open window for bad actors in every community. State-sponsored actors are developing custom malware to use routers for persistence and espionage. Cybercriminals are also leveraging routers and related infrastructure for residential proxies and to recruit into botnets. Our discoveries reaffirm the need for heightened awareness of the OT/IoT edge devices that are so often neglected.”
Sierra Wireless and OpenDNS have issued patches for the identified vulnerabilities. TinyXML is an abandoned open source project, so the upstream vulnerabilities will not be fixed and must be addressed downstream.
For more information, download the full report, “SIERRA:21 – Living on the Edge,” now at https://www.forescout.com/resources/sierra21-vulnerabilities.
Additional Resources:
- View the on-demand webinar: https://www.brighttalk.com/central/account/616385/channel/13809/video/602171
- Read more insight from Forescout Research: Hacktivists attack U.S. water treatment plant – analysis and implications
About Forescout
Forescout Technologies, Inc., a global cybersecurity leader, continuously identifies, protects and helps ensure the compliance of all managed and unmanaged connected cyber assets – IT, IoT, IoMT and OT. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide vendor-agnostic, automated cybersecurity at scale. The Forescout® Platform delivers comprehensive capabilities for network security, risk and exposure management, and extended detection and response. With seamless context sharing and workflow orchestration via ecosystem partners, it enables customers to more effectively manage cyber risk and mitigate threats.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20231205915662/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Aster Guardians Global Nursing Award 2026 Worth $250,000 Extends Deadline Till 11th January 202631.12.2025 14:08:00 CET | Press release
Due to an extraordinary global response of over 134,000 registrations from 214 countries, the submission deadline has been extended.Nurses worldwide can submit their nominations via www.asterguardians.com The Aster Guardians Global Nursing Award 2026, an initiative from Aster DM Healthcare – a leading integrated healthcare provider, has announced the extension of its deadline to January 11, 2026. The awards have already received over 134,000 registrations from 214 countries, highlighting its growing global reach and recognition among nurses worldwide. Nurses from around the world can submit their nominations through the dedicated platform at www.asterguardians.com. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251231986766/en/ Aster Guardians Global Nursing Award worth USD 250,000 (Photo: AETOSWire) This year, the prestigious award will be hosted in New Delhi, India, celebrating nursing excellence on a truly global stage. T
Tecnotree Included as a Representative Provider in Gartner® Innovation Insight: AI SOC Agents Accelerate CSP SecOps Transformation31.12.2025 11:59:00 CET | Press release
Tecnotree, a global digital platform and services provider for communications service providers (CSPs), today announced that it has been referenced as a Representative Provider alongside Google, Anthropic, Dropzone AI, DRUID, Palo Alto Networks, and Pegasystems in the Gartner® Innovation Insight: “AI SOC Agents Accelerate CSP SecOps Transformation,” published in December 2025. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251231210303/en/ Tecnotree Included as a Representative Provider in Gartner® Innovation Insight: AI SOC Agents Accelerate CSP SecOps Transformation The Gartner Innovation Insight examines the emerging role of AI-driven Security Operations Centre (SOC) agents in CSP environments, outlining how these agents are used to automate and augment security operations across signalling, core networks, RAN, Open RAN, and roaming domains. The research discusses use cases such as alert triage, investigation support, thr
UAE’s Medcare Treats First International SMA Patient With Revolutionary Intrathecal Gene Therapy30.12.2025 15:15:00 CET | Press release
The newly licensed intrathecal gene therapy expands life-changing treatment options for children and adults affected by SMA Medcare Women & Children Hospital has successfully administered a pioneering intrathecal gene therapy for Spinal Muscular Atrophy (SMA) to Hulus, a three-year-old patient from Turkey. This milestone positions Medcare among the first private healthcare providers worldwide to offer this innovative treatment to an older international patient, overcoming previous age and weight limitations. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251230695275/en/ World's first international patient, who received intrathecal gene therapy at Medcare Royal Hospital in Dubai, UAE, along with parents, and the hospital team. (Photo: AETOSWire) SMA is a rare neuromuscular disorder that progressively weakens muscles responsible for movement and breathing. This newly licensed one-time therapy addresses the root genetic cause
Amazfit Introduces Active Max: Bigger, Brighter, and Built for Maximum Performance30.12.2025 09:00:00 CET | Press release
The newest member of the Active family blends new design, expanded storage, and longer battery to help users train smarter and reach their goals with confidence. Amazfit, a leading global smart wearable brand by Zepp Health (NYSE: ZEPP), today announces the Amazfit Active Max, the newest member of the Amazfit Active family. Built for everyday athletes and anyone looking to elevate their wellness routine, Active Max blends a 1.5″ ultra-bright AMOLED display, up to 25 days of battery life, easy podcast listening and advanced training tools to support consistent training and clearer visibility across any activity. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251230279762/en/ Bigger Display. Max Clarity: A 1.5″ ultra-bright AMOLED display delivers exceptional clarity in any setting—whether in the gym, outdoors, or on the move. With up to 3,000 nits of peak brightness, the screen ensures real-time stats are always easy to read.
2026 Future of Fitness Report: Experts from Coherent Solutions Turn Years of Fitness Industry Software Engineering Work Into a Guidebook on Future-proof Digital Transformation in Fitness29.12.2025 18:48:00 CET | Press release
Coherent Solutions has released its 2026 Future of Fitness report, capturing years of domain knowledge from helping emerging and global fitness brands drive digital transformation, innovate, and improve member engagement. “The Future of Fitness: Winning with Digital Value Creation” takes lessons from real projects and fitness enthusiasts, turning them into a guidebook for the next era of fitness. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251229965712/en/ New Fitness Tech Whitepaper by Coherent Solutions While the global fitness market is on track to surpass $257 billion, and brands are expanding globally, pioneering new regions, and implementing new technologies, the report highlights the most effective growth trajectory in acknowledging the importance of technology as equal to supporting the fitness community. "Most people only spend 3–5 hours a week in a gym. That leaves 160+ hours where their choices and habits are i
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
