Business Wire

CA-FORESCOUT

6.12.2023 07:02:34 CET | Business Wire | Press release

Share
Critical Infrastructure Still at High Risk: Forescout Research Spotlights 21 New Vulnerabilities

Forescout, a global cybersecurity leader, today released “SIERRA:21 – Living on the Edge,” an analysis of 21 newly discovered vulnerabilities within OT/IoT routers and open-source software components. The report — produced by Forescout Research – Vedere Labs, a leading global team dedicated to uncovering vulnerabilities in critical infrastructure — emphasizes the continued risk to critical infrastructure and sheds light on possible mitigations.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231205915662/en/

To view this piece of content from mms.businesswire.com, please give your consent at the top of this page.

Sierra:21 Infographic (Source: Forescout)

“SIERRA:21 – Living on the Edge” features research into Sierra Wireless AirLink cellular routers and some of its open-source components, such as TinyXML and OpenNDS. Sierra Wireless routers are popular — an open database of Wi-Fi networks shows 245,000 networks worldwide running Sierra Wireless for a variety of applications. For example, Sierra Wireless routers are used for police vehicles connecting to a central network management system or to stream surveillance video, in manufacturing plants for industrial asset monitoring, in healthcare facilities providing temporary connectivity and to manage electric vehicle charging stations. The 21 new vulnerabilities have the potential to stop vital communications that could impact everyday life.

Read the blog: Forescout Vedere Labs discloses 21 new vulnerabilities affecting OT/IoT routers

Forescout Research further finds:

  • The attack surface is expansive with 86,000 vulnerable routers still exposed online. Less than 10% of these routers are confirmed to be patched against known previous vulnerabilities found since 2019.
  • Regions with the highest number of exposed devices includes:
    • 68,605 devices in The United States
    • 5,580 devices in Canada
    • 3,853 devices in Australia
    • 2,329 devices in France
    • 1,001 devices in Thailand
  • Among the 21 vulnerabilities, one has critical severity (CVSS score 9.6), nine have high severity and 11 have medium severity. These vulnerabilities allow attackers to steal credentials, take control of a router by injecting malicious code, persist on the device and use it as an initial access point into critical networks.
  • Patching can’t fix everything. 90 percent of devices exposing a specific management interface have reached end of life, meaning they cannot be further patched.
  • It’s an uphill battle to secure supply chain components. Open-source software elements continue to go unchecked and increase the attack surface of critical devices, leading to vulnerabilities that may be hard for organizations to track and mitigate.

“We are raising the alarm today because there remain thousands of OT/IoT devices representing an increased attack surface that requires attention,” advises Elisa Constante, VP of Research, Forescout Research – Vedere Labs. “Vulnerabilities impacting critical infrastructure are like an open window for bad actors in every community. State-sponsored actors are developing custom malware to use routers for persistence and espionage. Cybercriminals are also leveraging routers and related infrastructure for residential proxies and to recruit into botnets. Our discoveries reaffirm the need for heightened awareness of the OT/IoT edge devices that are so often neglected.”

Sierra Wireless and OpenDNS have issued patches for the identified vulnerabilities. TinyXML is an abandoned open source project, so the upstream vulnerabilities will not be fixed and must be addressed downstream.

For more information, download the full report, “SIERRA:21 – Living on the Edge,” now at https://www.forescout.com/resources/sierra21-vulnerabilities.

Additional Resources:

About Forescout

Forescout Technologies, Inc., a global cybersecurity leader, continuously identifies, protects and helps ensure the compliance of all managed and unmanaged connected cyber assets – IT, IoT, IoMT and OT. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide vendor-agnostic, automated cybersecurity at scale. The Forescout® Platform delivers comprehensive capabilities for network security, risk and exposure management, and extended detection and response. With seamless context sharing and workflow orchestration via ecosystem partners, it enables customers to more effectively manage cyber risk and mitigate threats.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20231205915662/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

TradingHub Secures Strategic Investment From Nordic Capital to Accelerate Next Phase of Growth16.3.2026 17:00:00 CET | Press release

TradingHub, a leading provider of trade surveillance technology for global financial institutions, has agreed to partner with Nordic Capital which will become the company’s majority shareholder. The investment marks a significant milestone in TradingHub’s journey and provides strong backing to support the company’s continued growth and innovation. Existing investor Summit Partners and TradingHub’s co-founder Neil Walker will continue to hold minority positions in the company following the close of the transaction. With the support of Nordic Capital, TradingHub will accelerate its expansion across global markets while continuing to invest in the development of its trade surveillance platform. The company plans to further strengthen its capabilities across asset classes, including equities, and continue its expansion into new markets and geographies. Founded in 2010 and today operating from offices in London, Toronto, Singapore and Sydney, TradingHub has built a highly differentiated tec

Madinah Hosts Third Umrah and Ziyarah Forum with Strong International Participation16.3.2026 16:10:00 CET | Press release

The third edition of the Umrah and Ziyarah Forum will commence in Madinah on Monday, March 30, 2026. The forum is organized by the Ministry of Hajj and Umrah, in partnership with the Pilgrim Experience Program, at the King Salman International Convention Center, with wide participation from business leaders, decision-makers, and specialists in the Umrah and Ziyarah services ecosystem from around the world to exchange expertise and explore ways to further enrich the experience of the Guests of Allah. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260316471639/en/ Madinah Hosts Third Umrah and Ziyarah Forum with Strong International Participation (Photo: AETOSWire) This year’s edition builds on the success of the forum's previous editions, reaffirming its position as a global platform for advancing the Umrah and Ziyarah services ecosystem. It focuses on enhancing services for Umrah performers and visitors, in line with the gro

Capcom’s Official Street Fighter 6 World Championship Tournaments Attract Record-high 20,000 Attendees16.3.2026 14:00:00 CET | Press release

– Capcom aims to accelerate growth of the global competitive scene with a larger total prize pool of over $2.1 million in the upcoming 2026 season – Capcom Co., Ltd. (TOKYO:9697) today announced that Capcom Cup 12 and Street Fighter League: World Championship 2025, its official world championship tournaments to determine the top Street Fighter 6 competitors, which were held at Ryogoku Kokugikan Arena from March 11-15, achieved a record-high of 20,000 attendees, concluding with great success. At Capcom Cup 12, which features matches against individual players, SAHARA (21 years old), who is a first‑year professional player, claimed the championship title in his debut appearance, while in the team-based competition Street Fighter League: World Championship 2025, Japanese representatives REJECT were the winning team. Capcom additionally announced that it will hold next season’s Capcom Cup 13 and Street Fighter League: World Championship 2026 at Ryogoku Kokugikan Arena. Furthermore, the com

Capcom’s Resident Evil Requiem Sales Exceed 6 Million Units!16.3.2026 14:00:00 CET | Press release

– Capcom also plans to release additional game content – Capcom Co., Ltd. (TOKYO:9697) today announced that worldwide sales of Resident Evil Requiem, released on February 27, 2026, now exceed 6 million units, which is the fastest that a title in the series has reached this milestone. Resident Evil Requiem is the latest installment in the Resident Evil series, which offers photorealistic visuals and a deep sense of immersion. Players can enjoy the elevated essence of the survival horror experience by the interplay between intense fear and exhilarating action, made possible by two protagonists. Going forward, Capcom plans to implement several measures, such as ongoing support and additional game content, so players can continue to enjoy the title longer. In addition, the Resident Evil series will celebrate its 30th anniversary on March 22,2026. Capcom is readying various plans for this anniversary to delight series fans, such as a collaboration between Universal Studios Japan and Residen

Helical Fusion Announces Construction Site for Phase 1 of “Helix HARUKA,” Marking Transition to Manufacturing and Assembly of Fusion Hardware16.3.2026 14:00:00 CET | Press release

Advances one of Japan’s leading public-private partnership initiatives for fusion commercialization with NIFS and industrial partners Helical Fusion Co., Ltd. (Head Office: Chuo-ku, Tokyo; CEO: Takaya Taguchi; “Helical Fusion”), a Japanese fusion energy company advancing the Helix Program and developing the Helical Stellarator for commercial fusion power plants, announced the construction site for Phase 1 of Helix HARUKA, its Integrated Demonstration Device. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260316066384/en/ Concept image of Helix HARUKA, Helical Fusion’s integrated demonstration device Phase 1—the magnet demonstration phase—will be built in a dedicated workspace for the joint research group formed by Helical Fusion and the National Institute for Fusion Science (NIFS), located on the NIFS campus. Helical Fusion has already begun manufacturing phase and site build-out, with the aim of conducting coil current (ene

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye