CA-FORESCOUT
6.12.2023 07:02:34 CET | Business Wire | Press release
Forescout, a global cybersecurity leader, today released “SIERRA:21 – Living on the Edge,” an analysis of 21 newly discovered vulnerabilities within OT/IoT routers and open-source software components. The report — produced by Forescout Research – Vedere Labs, a leading global team dedicated to uncovering vulnerabilities in critical infrastructure — emphasizes the continued risk to critical infrastructure and sheds light on possible mitigations.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231205915662/en/
Sierra:21 Infographic (Source: Forescout)
“SIERRA:21 – Living on the Edge” features research into Sierra Wireless AirLink cellular routers and some of its open-source components, such as TinyXML and OpenNDS. Sierra Wireless routers are popular — an open database of Wi-Fi networks shows 245,000 networks worldwide running Sierra Wireless for a variety of applications. For example, Sierra Wireless routers are used for police vehicles connecting to a central network management system or to stream surveillance video, in manufacturing plants for industrial asset monitoring, in healthcare facilities providing temporary connectivity and to manage electric vehicle charging stations. The 21 new vulnerabilities have the potential to stop vital communications that could impact everyday life.
Read the blog: Forescout Vedere Labs discloses 21 new vulnerabilities affecting OT/IoT routers
Forescout Research further finds:
- The attack surface is expansive with 86,000 vulnerable routers still exposed online. Less than 10% of these routers are confirmed to be patched against known previous vulnerabilities found since 2019.
-
Regions with the highest number of exposed devices includes:
- 68,605 devices in The United States
- 5,580 devices in Canada
- 3,853 devices in Australia
- 2,329 devices in France
- 1,001 devices in Thailand
- Among the 21 vulnerabilities, one has critical severity (CVSS score 9.6), nine have high severity and 11 have medium severity. These vulnerabilities allow attackers to steal credentials, take control of a router by injecting malicious code, persist on the device and use it as an initial access point into critical networks.
- Patching can’t fix everything. 90 percent of devices exposing a specific management interface have reached end of life, meaning they cannot be further patched.
- It’s an uphill battle to secure supply chain components. Open-source software elements continue to go unchecked and increase the attack surface of critical devices, leading to vulnerabilities that may be hard for organizations to track and mitigate.
“We are raising the alarm today because there remain thousands of OT/IoT devices representing an increased attack surface that requires attention,” advises Elisa Constante, VP of Research, Forescout Research – Vedere Labs. “Vulnerabilities impacting critical infrastructure are like an open window for bad actors in every community. State-sponsored actors are developing custom malware to use routers for persistence and espionage. Cybercriminals are also leveraging routers and related infrastructure for residential proxies and to recruit into botnets. Our discoveries reaffirm the need for heightened awareness of the OT/IoT edge devices that are so often neglected.”
Sierra Wireless and OpenDNS have issued patches for the identified vulnerabilities. TinyXML is an abandoned open source project, so the upstream vulnerabilities will not be fixed and must be addressed downstream.
For more information, download the full report, “SIERRA:21 – Living on the Edge,” now at https://www.forescout.com/resources/sierra21-vulnerabilities.
Additional Resources:
- View the on-demand webinar: https://www.brighttalk.com/central/account/616385/channel/13809/video/602171
- Read more insight from Forescout Research: Hacktivists attack U.S. water treatment plant – analysis and implications
About Forescout
Forescout Technologies, Inc., a global cybersecurity leader, continuously identifies, protects and helps ensure the compliance of all managed and unmanaged connected cyber assets – IT, IoT, IoMT and OT. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide vendor-agnostic, automated cybersecurity at scale. The Forescout® Platform delivers comprehensive capabilities for network security, risk and exposure management, and extended detection and response. With seamless context sharing and workflow orchestration via ecosystem partners, it enables customers to more effectively manage cyber risk and mitigate threats.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20231205915662/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Navan Invests in European Footprint with New Partnerships22.6.2026 10:01:00 CEST | Press release
New integrations with ITA Airways, Caledonian Sleeper, and Virtuo elevate localized inventory across Europe Navan (NASDAQ: NAVN), the global AI-powered business travel and expense platform, today announced new integrations with European travel suppliers. Navan will add to its platform a direct New Distribution Capability (NDC) connection with Italy’s national air carrier, ITA Airways; overnight rail services in the UK with Caledonian Sleeper; and mobile-first car rental bookings in France with Virtuo. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260622904121/en/ New integrations with ITA Airways, Caledonian Sleeper, and Virtuo elevate localized inventory across Europe “We’re seeing incredible momentum across Europe, bookings to and from the continent are up year-over-year, and to truly serve the European market you have to continually invest locally,” said Michael Riegel, Chief Customer Officer at Navan. “By bringing ITA’s
Finalists Announced for the Second Edition of the Reply AI Music Contest, the International Competition Exploring the Relationship Between AI and Live Performance22.6.2026 10:00:00 CEST | Press release
The jury will announce the winners on Saturday, 4 July, on the stage of Kappa FuturFestival in Turin Music and artificial intelligence come together at the Reply AI Music Contest to explore the relationship between AI and live performance. The competition, created by Reply and organized in collaboration with Kappa FuturFestival — one of Europe’s leading festivals dedicated to electronic music and cultural innovation — announces the five finalists selected by an international jury of professionals from music and creative industries: Agoria, Max Cooper, Fleur Shore, Tini Gessler, Ali Demirel, Albi Scotti, Oliver Bohl and Sarah Grimaldi. The finalists represent a new generation of innovators using AI to explore new forms of integration between sound, visual arts and live performance. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260622111182/en/ Finalists announced for the second edition of the Reply AI Music Contest, the inte
Zilliz Launches Vector Lakebase, Extending the World's Most Adopted Vector Database into a Unified Data Platform for AI22.6.2026 08:00:00 CEST | Press release
Available now in public preview on Zilliz Cloud, Vector Lakebase keeps production vector search at its core and adds shared lake-native storage and on-demand compute — bringing real-time serving, interactive discovery, and batch analytics onto one data foundation. Zilliz, the company behind Milvus, the world's most widely adopted open-source vector database, today announced the public preview of Zilliz Vector Lakebase, a major Zilliz Cloud release that pairs the production vector database with a shared, lake-native data foundation. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260621822926/en/ Vector Lakebase keeps Zilliz Cloud's real-time vector search at the core — the engine Zillow, OpenEvidence, Exa, Filevine, MiniMax, and more than 10,000 enterprises and AI teams already rely on — and extends it with three new ways to operate on the same data: interactive discovery, large-scale batch analytics, and search directly on e
Andersen Global styrker sin tilstedeværelse i Indien med JMP Advisors21.6.2026 16:16:00 CEST | Pressemeddelelse
Andersen Global indgår en samarbejdsaftale med JMP Advisors i Indien og tilføjer skattemæssig ekspertise til virksomhedens eksisterende juridiske kapaciteter i landet. JMP Advisors tilbyder rådgivning inden for skat, lovgivning og transaktioner til både nationale og multinationale klienter, der opererer i komplekse forretningsmiljøer i konstant udvikling. Firmaet leverer ydelser, der spænder over international og indisk skat, transfer pricing, international strukturering, rådgivning om udenlandske investeringer, transaktionsstøtte, generationsskifteplanlægning og regulatoriske forhold. Dets klienter omfatter multinationale selskaber, vækstvirksomheder, virksomheder støttet af kapitalfonde og venturekapital samt formuende privatpersoner og familier. "Vores fokus har altid været at levere klar og handlingsorienteret vejledning, der hjælper kunder med at navigere i komplekse situationer og drive deres virksomhed med en tydelig kurs," udtalte Jairaj Purandare, grundlægger og formand for JM
Special Olympics Airlift Takes Flight Nationwide; Dove 1 Arrives at St. Paul Downtown Airport19.6.2026 17:09:00 CEST | Press release
Approximately 130 Cessna, Beechcraft and Hawker aircraft and volunteer pilots mobilize to transport more than 800 Special Olympics athletes and coaches to the 2026 Special Olympics USA Games The 2026 Special Olympics Airlift officially took flight today as all participating Cessna, Beechcraft and Hawker aircraft, known as Doves, departed from airports across the country. Dove 1 for arrival day, a Cessna Citation Latitude generously operated by Prent Corporation, landed at St. Paul Downtown Airport (STP) carrying Special Olympic athletes and delegation members, signaling the start of Airlift arrivals for the Special Olympics USA Games. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260619085293/en/ Special Olympics Airlift takes flight nationwide; Dove 1 arrives at St. Paul Downtown Airport (Photo credit: Textron Aviation). The arrival signals the start of the world’s largest cumulative peacetime airlift spanning more than 40
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
