CA-FORESCOUT
Forescout, a global cybersecurity leader, today released “SIERRA:21 – Living on the Edge,” an analysis of 21 newly discovered vulnerabilities within OT/IoT routers and open-source software components. The report — produced by Forescout Research – Vedere Labs, a leading global team dedicated to uncovering vulnerabilities in critical infrastructure — emphasizes the continued risk to critical infrastructure and sheds light on possible mitigations.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231205915662/en/
Sierra:21 Infographic (Source: Forescout)
“SIERRA:21 – Living on the Edge” features research into Sierra Wireless AirLink cellular routers and some of its open-source components, such as TinyXML and OpenNDS. Sierra Wireless routers are popular — an open database of Wi-Fi networks shows 245,000 networks worldwide running Sierra Wireless for a variety of applications. For example, Sierra Wireless routers are used for police vehicles connecting to a central network management system or to stream surveillance video, in manufacturing plants for industrial asset monitoring, in healthcare facilities providing temporary connectivity and to manage electric vehicle charging stations. The 21 new vulnerabilities have the potential to stop vital communications that could impact everyday life.
Read the blog: Forescout Vedere Labs discloses 21 new vulnerabilities affecting OT/IoT routers
Forescout Research further finds:
- The attack surface is expansive with 86,000 vulnerable routers still exposed online. Less than 10% of these routers are confirmed to be patched against known previous vulnerabilities found since 2019.
-
Regions with the highest number of exposed devices includes:
- 68,605 devices in The United States
- 5,580 devices in Canada
- 3,853 devices in Australia
- 2,329 devices in France
- 1,001 devices in Thailand
- Among the 21 vulnerabilities, one has critical severity (CVSS score 9.6), nine have high severity and 11 have medium severity. These vulnerabilities allow attackers to steal credentials, take control of a router by injecting malicious code, persist on the device and use it as an initial access point into critical networks.
- Patching can’t fix everything. 90 percent of devices exposing a specific management interface have reached end of life, meaning they cannot be further patched.
- It’s an uphill battle to secure supply chain components. Open-source software elements continue to go unchecked and increase the attack surface of critical devices, leading to vulnerabilities that may be hard for organizations to track and mitigate.
“We are raising the alarm today because there remain thousands of OT/IoT devices representing an increased attack surface that requires attention,” advises Elisa Constante, VP of Research, Forescout Research – Vedere Labs. “Vulnerabilities impacting critical infrastructure are like an open window for bad actors in every community. State-sponsored actors are developing custom malware to use routers for persistence and espionage. Cybercriminals are also leveraging routers and related infrastructure for residential proxies and to recruit into botnets. Our discoveries reaffirm the need for heightened awareness of the OT/IoT edge devices that are so often neglected.”
Sierra Wireless and OpenDNS have issued patches for the identified vulnerabilities. TinyXML is an abandoned open source project, so the upstream vulnerabilities will not be fixed and must be addressed downstream.
For more information, download the full report, “SIERRA:21 – Living on the Edge,” now at https://www.forescout.com/resources/sierra21-vulnerabilities.
Additional Resources:
- View the on-demand webinar: https://www.brighttalk.com/central/account/616385/channel/13809/video/602171
- Read more insight from Forescout Research: Hacktivists attack U.S. water treatment plant – analysis and implications
About Forescout
Forescout Technologies, Inc., a global cybersecurity leader, continuously identifies, protects and helps ensure the compliance of all managed and unmanaged connected cyber assets – IT, IoT, IoMT and OT. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide vendor-agnostic, automated cybersecurity at scale. The Forescout® Platform delivers comprehensive capabilities for network security, risk and exposure management, and extended detection and response. With seamless context sharing and workflow orchestration via ecosystem partners, it enables customers to more effectively manage cyber risk and mitigate threats.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20231205915662/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
SPIE, the International Society for Optics and Photonics, Announces Its 2026 Society Awards8.1.2026 18:26:00 CET | Press release
The 22 award recipients represent an exciting range of stellar achievements across light-based sciences and technologies Today, the Awards Committee of SPIE, the international society for optics and photonics, announced the recipients of its prestigious annual awards. Honoring transformative advancements across a range of professional areas — including medicine, astronomy, lithography, optical metrology, optical design, and community leadership — the Society's awards recognize technical accomplishments as well as committed service to SPIE and support of its organizational mission. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260108227351/en/ SPIE, the international society for optics and photonics, awarded their Gold Medal to Maryellen Giger (pictured here with her team) for pioneering work in computer-aided diagnosis and image analysis/AI, significant impact on clinical translation, and supporting the next generation of m
PUMA Appoints Nadia Kokni as Vice President Global Brand Marketing8.1.2026 16:30:00 CET | Press release
Sports company PUMA has appointed Nadia Kokni as Vice President, Global Brand Marketing, effective January 1, 2026. Nadia joins PUMA’s global leadership team and reports directly to Chief Brand Officer Maria Valdes. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260108099913/en/ Sports company PUMA has appointed Nadia Kokni as Vice President, Global Brand Marketing, effective January 1, 2026. Nadia joins PUMA’s global leadership team and reports directly to Chief Brand Officer Maria Valdes. In her new role as PUMA’s most senior global marketing leader, Nadia will oversee brand marketing strategy, brand marketing creative direction, integrated marketing and communication globally. Her appointment comes as PUMA accelerates its global brand ambition and sharpens storytelling around its product icons and innovation pipeline. Nadia brings deep international experience shaping and transforming leading global brands across the spor
Golub Capital Continues Strong Track Record of Consistent Results in 20258.1.2026 16:00:00 CET | Press release
Another Year of “Good Boring” through SpecializationClosed $25+ Billion in Financing Commitments in 2025Raised a Firm Record $20.5 Billion of New Investment CapitalLaunched GP-Led Secondaries Strategy Golub Capital delivered another year of “good boring,” consistent results for its stakeholders in 2025, aided by its commitment to specialization. “We have long believed that specialization is a key source of competitive advantage for Golub Capital,” said David Golub, President of the Firm. “The past year validated this. Our deep relationships, scale and expertise enabled us to continue delivering strong results for investors, sponsors, portfolio companies and our team despite a muted M&A environment and high levels of credit stress across the private equity ecosystem. We are grateful for our clients’ trust and remain committed to building long-term, win-win partnerships that endure through market cycles.” 2025 Highlights, based on preliminary results:1 Delivering strong credit performanc
Xsolla Kicks Off Two Weeks of Industry Programming, Community Events, and Expanding Support for Global Developers Across the UK at the Industry’s Biggest Winter Event8.1.2026 16:00:00 CET | Press release
Coordinated Activations in the UK Underscore Xsolla’s Ongoing Commitment to Building All The Things for the Video Community in Europe Xsolla, a global video game commerce company that helps developers launch, grow, and monetize their games, today announces a comprehensive program of events and activations across the United Kingdom taking place from January 10 to 22, 2026. This coordinated programming schedule reflects Xsolla’s continued investment in the UK and European games ecosystem. Capitalizing on a pivotal moment in the global games calendar, Xsolla is bringing developers, partners, and creators together through partnerships, live events, thought leadership, and community building. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260108943976/en/ (Graphic: Xsolla) “Pocket Gamer Connects London brings together one of the most diverse and forward-thinking communities in the mobile global games industry,” said Berkley Egene
AMRA Medical Introduces AMRA® BCP Scan in the Netherlands Through a Strategic Partnership with Prescan, a National Preventative Health Leader8.1.2026 15:31:00 CET | Press release
AMRA Medical, the global leader in MRI-based fat distribution and muscle composition analytics, alongside Dutch preventative healthcare leader Prescan, are pleased to announce the official launch of our cutting-edge AMRA® BCP Scan service, powered by AMRA® Profiler (CE, NB 2862), in the Netherlands. The launch, which marks BCP Scan’s third new market entry of 2025 (Sweden & Germany), expands the availability of our service within the EU into the Netherlands through an exclusive partnership with Prescan, an independent health & wellness clinic in Baarn which specializes in preventive health screenings and care. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260108381985/en/ AMRA® BCP Scan available at Prescan AMRA’s CEO, Olof Dahlqvist Leinhard, stated, “This is another important step in bringing our mission of driving scientific breakthroughs into the clinic by enabling deeper understanding of health and disease through MRI-
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
