CISA Releases Five ICS Advisories Covering Vulnerabilities, and Exploits Surrounding ICS
On Tue, Dec 2, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released five critical advisories concerning vulnerabilities in Industrial Control Systems (ICS). These advisories address significant security threats in industrial…
On Tue, Dec 2, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released five critical advisories concerning vulnerabilities in Industrial Control Systems (ICS). These advisories address significant security threats in industrial environments globally.
The advisories highlight vulnerabilities and active exploits impacting systems in manufacturing, power generation, and medical device operations worldwide. The release underscores the increasing concern about the targeted nature of ICS attacks, which have the potential to disrupt essential infrastructure.
Industrial control systems are integral to critical infrastructure, managing operations from power plants to water treatment facilities and medical equipment. Vulnerabilities in these systems can provide pathways for attackers to access sensitive operational technology networks.
The advisories target several vendors, including Mitsubishi Electric, Iskra, and Mirion Technologies, affecting a wide range of industrial equipment. Organizations using these systems must deploy security updates while maintaining continuous operations, presenting a challenge that emphasizes the urgency of these warnings.
Vulnerability Exploitation and Attack Surface
The identified vulnerabilities include authentication bypasses, remote code execution flaws, and improper input validation issues. Attackers can exploit these weaknesses by sending specially crafted requests to systems, potentially gaining unauthorized access to critical operational functions.
Understanding the attack surface is crucial for organizations operating these systems. Network segmentation is recommended to ensure vulnerable systems remain isolated from external internet connectivity. CISA advises administrators to apply security patches promptly, enforce strong authentication mechanisms, and deploy network monitoring solutions to detect suspicious activities.
These advisories address significant security threats in industrial environments globally.
Advisory ID Vendor Product CVE Vulnerability Type CVSS v3.1 CVSS v4 Affected Versions Risk Description Exploitation
ICSA-25-336-01 Industrial Video & Control Longwatch CVE-2025-13658 Improper Control of Generation of Code (Code Injection) 9.8 9.3 6.309 to 6.334 Remote code execution with SYSTEM-level privileges Remotely exploitable with low attack complexity
ICSA-25-336-02 Iskra iHUB and iHUB Lite CVE-2025-13510 Missing Authentication for Critical Function 9.1 9.3 All Versions Device reconfiguration, firmware updates, system manipulation without credentials Remotely exploitable with low attack complexity
ICSMA-25-336-01 Mirion Medical EC2 Software NMIS BioDose CVE-2025-64642 Incorrect Permission Assignment for Critical Resource 8.0 7.1 Prior to 23.0 Modification of program executables and libraries Locally exploitable with low attack complexity
ICSA-25-201-01 Mitsubishi Electric CNC Series CVE-2016-2542 Uncontrolled Search Path Element 7.0 N/A Multiple versions Malicious code execution via DLL hijacking Locally exploitable with user interaction required
Organizations are advised to prioritize patching systems identified in the advisories, especially those connected to production environments where operational disruption could impact public safety and economic stability.
The release reflects CISA's commitment to safeguarding industrial infrastructure through timely disclosures and actionable guidance. These advisories provide a blueprint for defensive measures, aiding organizations in strengthening their security posture against determined threat actors targeting industrial systems.
Based on reporting by Cyber Security News.
