CA-FORESCOUT
Forescout, a global cybersecurity leader, today released “SIERRA:21 – Living on the Edge,” an analysis of 21 newly discovered vulnerabilities within OT/IoT routers and open-source software components. The report — produced by Forescout Research – Vedere Labs, a leading global team dedicated to uncovering vulnerabilities in critical infrastructure — emphasizes the continued risk to critical infrastructure and sheds light on possible mitigations.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231205915662/en/
Sierra:21 Infographic (Source: Forescout)
“SIERRA:21 – Living on the Edge” features research into Sierra Wireless AirLink cellular routers and some of its open-source components, such as TinyXML and OpenNDS. Sierra Wireless routers are popular — an open database of Wi-Fi networks shows 245,000 networks worldwide running Sierra Wireless for a variety of applications. For example, Sierra Wireless routers are used for police vehicles connecting to a central network management system or to stream surveillance video, in manufacturing plants for industrial asset monitoring, in healthcare facilities providing temporary connectivity and to manage electric vehicle charging stations. The 21 new vulnerabilities have the potential to stop vital communications that could impact everyday life.
Read the blog: Forescout Vedere Labs discloses 21 new vulnerabilities affecting OT/IoT routers
Forescout Research further finds:
- The attack surface is expansive with 86,000 vulnerable routers still exposed online. Less than 10% of these routers are confirmed to be patched against known previous vulnerabilities found since 2019.
-
Regions with the highest number of exposed devices includes:
- 68,605 devices in The United States
- 5,580 devices in Canada
- 3,853 devices in Australia
- 2,329 devices in France
- 1,001 devices in Thailand
- Among the 21 vulnerabilities, one has critical severity (CVSS score 9.6), nine have high severity and 11 have medium severity. These vulnerabilities allow attackers to steal credentials, take control of a router by injecting malicious code, persist on the device and use it as an initial access point into critical networks.
- Patching can’t fix everything. 90 percent of devices exposing a specific management interface have reached end of life, meaning they cannot be further patched.
- It’s an uphill battle to secure supply chain components. Open-source software elements continue to go unchecked and increase the attack surface of critical devices, leading to vulnerabilities that may be hard for organizations to track and mitigate.
“We are raising the alarm today because there remain thousands of OT/IoT devices representing an increased attack surface that requires attention,” advises Elisa Constante, VP of Research, Forescout Research – Vedere Labs. “Vulnerabilities impacting critical infrastructure are like an open window for bad actors in every community. State-sponsored actors are developing custom malware to use routers for persistence and espionage. Cybercriminals are also leveraging routers and related infrastructure for residential proxies and to recruit into botnets. Our discoveries reaffirm the need for heightened awareness of the OT/IoT edge devices that are so often neglected.”
Sierra Wireless and OpenDNS have issued patches for the identified vulnerabilities. TinyXML is an abandoned open source project, so the upstream vulnerabilities will not be fixed and must be addressed downstream.
For more information, download the full report, “SIERRA:21 – Living on the Edge,” now at https://www.forescout.com/resources/sierra21-vulnerabilities.
Additional Resources:
- View the on-demand webinar: https://www.brighttalk.com/central/account/616385/channel/13809/video/602171
- Read more insight from Forescout Research: Hacktivists attack U.S. water treatment plant – analysis and implications
About Forescout
Forescout Technologies, Inc., a global cybersecurity leader, continuously identifies, protects and helps ensure the compliance of all managed and unmanaged connected cyber assets – IT, IoT, IoMT and OT. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide vendor-agnostic, automated cybersecurity at scale. The Forescout® Platform delivers comprehensive capabilities for network security, risk and exposure management, and extended detection and response. With seamless context sharing and workflow orchestration via ecosystem partners, it enables customers to more effectively manage cyber risk and mitigate threats.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20231205915662/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Incyte Announces New Data from Phase 3b TRuE-AD4 Trial of Opzelura® (Ruxolitinib Cream) in Adults with Moderate Atopic Dermatitis26.10.2025 01:55:00 CEST | Press release
Eight-week results from the TRuE-AD4 trial demonstrate treatment with Opzelura® (ruxolitinib cream) significantly improved the clinical signs of atopic dermatitis (AD), including improved itch as early as Day 2, and was well tolerated in adults with moderate AD who had an inadequate response, intolerance or contraindication to topical corticosteroids (TCSs) and topical calcineurin inhibitors (TCIs) At Week 8, 70% of patients treated with Opzelura achieved a ≥75% improvement in the Eczema Area and Severity Index (EASI75) and 61.3% achieved Investigator’s Global Assessment Treatment Success (IGA-TS), co-primary endpoints of the study Based on these results, Incyte expects to file a Type-II variation application for ruxolitinib cream 1.5% for the treatment of adults with moderate AD in the European Union (EU) by end of year Incyte (Nasdaq:INCY) today announced new data from the Phase 3b TRuE-AD4 study evaluating the efficacy and safety of Opzelura® (ruxolitinib cream) in adults with moder
MultiBank Group and Khabib Nurmagomedov Launch an Exclusive Worldwide Multi-Billion-Dollar Joint Venture to Build the World’s First Regulated Tokenized Sports Ecosystem25.10.2025 10:24:00 CEST | Press release
MultiBank Group, the world’s largest financial derivatives institution, has entered into an exclusive worldwide multi-billion-dollar joint venture with global sports icon and undefeated UFC champion Khabib Nurmagomedov (29-0) to create a first-of-its-kind regulated ecosystem connecting global finance, sports and technology. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251025540563/en/ MultiBank Group and Khabib Nurmagomedov Launch an Exclusive Worldwide Multi-Billion-Dollar Joint Venture to Build the World’s First Regulated Tokenized Sports Ecosystem The partnership will culminate in the creation of a multi-billion-dollar joint venture, MultiBank Khabib LLC, uniting two global powerhouses: MultiBank Group, a leader in regulated financial excellence, and Khabib Nurmagomedov, undefeated in the octagon and whose influence extends far beyond sport.The company will operate from MultiBank Group’s headquarters in Dubai, building
Altimetrik Completes Acquisition of SLK Software, Uniting Strengths to Unlock Value through AI-First and Digital Enablement24.10.2025 18:57:00 CEST | Press release
Altimetrik today announced the successful completion of its acquisition of SLK Software, marking a major milestone in the company’s journey to build a digital engineering powerhouse. As part of this transition, SLK Software will now operate under its new identity as “SLK, an Altimetrik company”. The integration brings together Altimetrik’s AI-first, data-led innovation capabilities with SLK’s strength in Intelligent Enterprise, Digital Operations, Intelligent Infrastructure and Automation and Quality Engineering - spanning the entire digital enablement value chain from strategy and design to engineering and managed services. Anchored in a Practitioner-Led approach, the unified organization merges deep domain expertise with modern platforms and digital operating models to deliver bite-size, outcome-focused execution that accelerates time-to-value. “I am thrilled to officially welcome the SLK team to Altimetrik, bringing together two organizations driven by purpose, innovation, and an un
Andersen Consulting samarbejder med Acronotics om at udbygge AI-styrede digitale transformationskapaciteter24.10.2025 17:55:00 CEST | Pressemeddelelse
Andersen Consulting styrker sine kompetencer inden for teknologi og forretningstransformation gennem en samarbejdsaftale med Acronotics, et hurtigt voksende digitalt konsulentfirma med hovedsæde i Storbritannien og afdelinger i USA og Indien. Som specialist i AI-drevet forretningstransformation samarbejder Acronotics med Fortune 500-virksomheder om at fremskynde den digitale transformation ved hjælp af kunstig intelligens. Virksomheden har dyb ekspertise inden for produktion, bankvirksomhed og finansielle tjenester, detailhandel, hurtigt omsættelige forbrugsgoder og højteknologiske industrier med stærkt fokus på AI/ML, generativ AI og RPA-teknologi. Acronotics leverer end-to-end-tjenester, herunder design, udvikling og implementering af Agentic AI og RPA-baserede procesautomatiseringsløsninger. Ved hjælp af sin egenudviklede automatiserede digitale medarbejderstyringsplatform, Radium.ai, hjælper virksomheden sine kunder med at administrere og overvåge deres digitale arbejdsstyrke effek
LambdaTest Unveils AI-Powered Web Scanner for Scalable Visual and Accessibility Testing24.10.2025 17:00:00 CEST | Press release
New browser-based solution empowers teams to detect visual bugs and ensure accessibility compliance at scale LambdaTest, a GenAI-native quality engineering platform, today announced the launch of LambdaTest Web Scanner, an advanced browser-based tool combining Visual UI Regression Testing and WCAG-compliant Accessibility Testing. It enables teams to identify and resolve visual and accessibility issues across web applications with unparalleled speed and precision. LambdaTest Web Scanner combines key features to streamline visual and accessibility testing. It offers Visual UI Regression Testing with SmartUI technology, enabling automated scans that detect layout changes and design mismatches across browsers and screen resolutions. It also supports WCAG-compliant Accessibility Testing, identifying violations and providing recommendations for inclusivity. The tool enables cross-browser and responsive testing across multiple browsers and 200+ mobile viewports, while smart scheduling allows
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
