Business Wire

CA-FORESCOUT

Share
Critical Infrastructure Still at High Risk: Forescout Research Spotlights 21 New Vulnerabilities

Forescout, a global cybersecurity leader, today released “SIERRA:21 – Living on the Edge,” an analysis of 21 newly discovered vulnerabilities within OT/IoT routers and open-source software components. The report — produced by Forescout Research – Vedere Labs, a leading global team dedicated to uncovering vulnerabilities in critical infrastructure — emphasizes the continued risk to critical infrastructure and sheds light on possible mitigations.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231205915662/en/

To view this piece of content from mms.businesswire.com, please give your consent at the top of this page.

Sierra:21 Infographic (Source: Forescout)

“SIERRA:21 – Living on the Edge” features research into Sierra Wireless AirLink cellular routers and some of its open-source components, such as TinyXML and OpenNDS. Sierra Wireless routers are popular — an open database of Wi-Fi networks shows 245,000 networks worldwide running Sierra Wireless for a variety of applications. For example, Sierra Wireless routers are used for police vehicles connecting to a central network management system or to stream surveillance video, in manufacturing plants for industrial asset monitoring, in healthcare facilities providing temporary connectivity and to manage electric vehicle charging stations. The 21 new vulnerabilities have the potential to stop vital communications that could impact everyday life.

Read the blog: Forescout Vedere Labs discloses 21 new vulnerabilities affecting OT/IoT routers

Forescout Research further finds:

  • The attack surface is expansive with 86,000 vulnerable routers still exposed online. Less than 10% of these routers are confirmed to be patched against known previous vulnerabilities found since 2019.
  • Regions with the highest number of exposed devices includes:
    • 68,605 devices in The United States
    • 5,580 devices in Canada
    • 3,853 devices in Australia
    • 2,329 devices in France
    • 1,001 devices in Thailand
  • Among the 21 vulnerabilities, one has critical severity (CVSS score 9.6), nine have high severity and 11 have medium severity. These vulnerabilities allow attackers to steal credentials, take control of a router by injecting malicious code, persist on the device and use it as an initial access point into critical networks.
  • Patching can’t fix everything. 90 percent of devices exposing a specific management interface have reached end of life, meaning they cannot be further patched.
  • It’s an uphill battle to secure supply chain components. Open-source software elements continue to go unchecked and increase the attack surface of critical devices, leading to vulnerabilities that may be hard for organizations to track and mitigate.

“We are raising the alarm today because there remain thousands of OT/IoT devices representing an increased attack surface that requires attention,” advises Elisa Constante, VP of Research, Forescout Research – Vedere Labs. “Vulnerabilities impacting critical infrastructure are like an open window for bad actors in every community. State-sponsored actors are developing custom malware to use routers for persistence and espionage. Cybercriminals are also leveraging routers and related infrastructure for residential proxies and to recruit into botnets. Our discoveries reaffirm the need for heightened awareness of the OT/IoT edge devices that are so often neglected.”

Sierra Wireless and OpenDNS have issued patches for the identified vulnerabilities. TinyXML is an abandoned open source project, so the upstream vulnerabilities will not be fixed and must be addressed downstream.

For more information, download the full report, “SIERRA:21 – Living on the Edge,” now at https://www.forescout.com/resources/sierra21-vulnerabilities.

Additional Resources:

About Forescout

Forescout Technologies, Inc., a global cybersecurity leader, continuously identifies, protects and helps ensure the compliance of all managed and unmanaged connected cyber assets – IT, IoT, IoMT and OT. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide vendor-agnostic, automated cybersecurity at scale. The Forescout® Platform delivers comprehensive capabilities for network security, risk and exposure management, and extended detection and response. With seamless context sharing and workflow orchestration via ecosystem partners, it enables customers to more effectively manage cyber risk and mitigate threats.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20231205915662/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

ASN Bank Signs a Contract With HCLTech to Accelerate Digital Transformation and Enhance Customer Experience17.12.2025 14:43:00 CET | Press release

HCLTech, a leading global technology company, today announced that it has been selected as a strategic partner by ASN Bank (formerly de Volksbank), the fourth-largest retail bank in the Netherlands. As part of its new strategy ‘Simplify and Grow’, ASN Bank aims to modernise and standardise its IT architecture, which will involve consolidating IT services, simplifying the vendor landscape and building a future-ready organisation. Under the multi-year agreement, HCLTech will support ASN Bank’s enterprise applications, and streamline services through a distributed delivery model to enhance efficiency and customer experience. Michel Ruijterman, Chief Information Officer, ASN Bank: “By signing this agreement , HCLTech’s proven track record in delivering scalable, innovative solutions tailored to the financial services sector means we can now confidently press on with streamlining our business by reducing the number of existing products and aligning the underlying processes and systems under

Riskified Announces Ascend 2026: “Intelligence in Motion” for the Next Era of Ecommerce17.12.2025 14:30:00 CET | Press release

From North America to the Asia-Pacific, Ascend 2026 will bring together leaders from the fraud and risk management community to define innovation-led ecommerce growth strategies Riskified (NYSE:RSKD), the leader in AI fraud and risk management for ecommerce, has announced that its premier global summit Ascend will once again be held as a global event series in 2026. Kicking off with North America (May) and continuing to Europe (June), Australia (August), China (September), and Japan (October), Ascend will convene each region’s largest merchants, industry experts, and technology leaders to discover the latest AI advancements and innovative strategies to propel ecommerce success. “Having pioneered using AI to fight ecommerce fraud and policy abuse over the past 10+ years, it’s equally exhilarating as it is concerning to witness the dramatic impact AI and agentic commerce are making on our industry. As risk grows more complex and shopper expectations rise, fraud teams and customer experie

Sinovac: Antigua Court Makes Interim Order Giving Board Control of the Company until the Trial of the Disputed 2025 Shareholder Meeting17.12.2025 13:00:00 CET | Press release

Sinovac Biotech Ltd. (NASDAQ: SVA) (SINOVAC or the Company), a leading provider of biopharmaceutical products in China, today announced that the Antigua High Court has ordered that the directors Mr. Simon Anderson, Mr. Shan Fu, Mr. Shuge Jiao, Mr. Yuk Lam Lo, Mr. Yumin Qiu, Mr. Yu Wang, Mr. Andrew Y. Yan and Mr. Yin Weidong (collectively, the Board), will comprise the Board of the Company until the trial listed in late April/early May 2026. The Antigua High Court decision arises from a hearing that took place on 27 October 2025, at which applicants SAIF Partners IV L.P., OrbiMed Partners Master Fund Limited and 1Globe Capital LLC each sought injunctions to confirm the composition of their respective favoured Boards, pending determination of a dispute over the outcome of the Company’s Special Shareholders Meeting on 8 July 2025 (the SSM Dispute). The hearing of the SSM Dispute has been scheduled to take place in the Antigua High Court in late April/early May 2026, with judgment to be de

Akamai and Visa Collaborate to Build Trust in Agentic Commerce17.12.2025 13:00:00 CET | Press release

Visa’s Trusted Agent Protocol to authenticate AI shopping agents and help prevent fraud across Akamai Cloud, strengthening the trust layer in agentic commerce Akamai Technologies, Inc. (NASDAQ: AKAM), the cybersecurity and cloud computing company that powers and protects business online, today announced a strategic collaboration with Visa (NYSE: V) to bring stronger identity, user recognition, and security controls to the emerging world of agentic commerce. Through its integration of Visa’s Trusted Agent Protocol with Akamai’s edge-based behavioral intelligence, user recognition, and bot and abuse protection, the companies will deliver the identity, authentication, and fraud controls required to let merchants confidently welcome AI agents with commerce intent into their digital storefronts. As autonomous AI agents increasingly browse, compare, and purchase on behalf of consumers, merchants face a new array of challenges. Merchants must now be able to differentiate this new type of legi

Mercans Launches the World’s First AI-Powered Globally Intelligent Workforce & Leave Management Engine17.12.2025 11:50:00 CET | Press release

A Unified Platform That Converts Unevaluated Time Data into Country- and Client-Compliant Workforce Transactions in Real Time Mercans, a global leader in payroll technology, workforce management, and HR SaaS solutions, today announced the launch of its next-generation Workforce Management (WFM) and Leave Management Engine - the world’s first platform capable of evaluating unevaluated time and attendance data against any country-specific legislation and client-specific policy framework, and converting it into fully evaluated, payroll-ready time transactions. This breakthrough engine fundamentally transforms how organizations manage time, attendance, and leave across borders by eliminating manual rule interpretation, fragmented systems, and country-by-country customizations. Solving a Global Workforce Challenge Traditional time and attendance systems capture raw or unevaluated data - clock-ins, clock-outs, absences, and leave requests - but fail to interpret that data in context. The res

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye