ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Cyble Urges Critical Vulnerability Fixes Affecting Industrial Systems

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-3980
+1 in the same advisory: …4872
The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations.

The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.

NVD description · AI analysis pending
8.8<1%
  • hitachienergy microscada pro sys600
  • hitachienergy microscada x sys600
CVE-2025-23120
Domain-User RCE via Deserialization in Veeam Backup & Replication

Veeam Backup & Replication contains a deserialization of untrusted data flaw (CWE-502) that allows remote code execution. Per the CVSS vector (AV:N/AC:L/PR:L/UI:N), the attack is network-reachable, straightforward to execute, and requires only low-privilege credentials — a regular domain user — with no user interaction; the vendor description states it yields RCE 'for domain users'. An attacker who obtains or already holds any domain-user account that can reach the backup server gains code execution with high confidentiality, integrity and availability impact, a foothold that is especially dangerous in backup infrastructure because those servers often hold credentials for large parts of the estate and are prime ransomware targets. Any organization running Veeam Backup & Replication is potentially affected. Veeam has released a fix (reported alongside its patch for the related CVE-2025-23121, rated 9.9, in the same product); a public technical write-up/PoC from watchTowr exists, the flaw is not yet in CISA's KEV, and EPSS assigns a 24% probability (98th percentile) of exploitation within 30 days.

Do: Upgrade Veeam Backup & Replication to the patched release specified in Veeam's security advisory; if you already applied the fix for the related CVE-2025-23121 (CVSS 9.9), verify you are on the newest build, as this flaw was disclosed alongside that patch. Restrict network access to backup infrastructure, review which domain accounts can reach the B&R server, and monitor for exploitation attempts given the public PoC and elevated EPSS score.

8.824% PoC
  • Veeam Backup & Replication
large≈ hundreds of thousands of enterprise installations (Veeam's flagship product; Veeam has publicly reported 550,000+ customers)
CVE-2025-25211
Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions.

Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login.

NVD description · AI analysis pending
9.8<1%
CVE-2025-26689
Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions.

Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.

NVD description · AI analysis pending
9.81%
Full article292 words · extracted from infosecurity-magazine.com · click to collapse

Multiple industrial control system (ICS) devices are affected by vulnerabilities carrying critical severity ratings up to a 9.9 CVSS base score.

In an April 10 blog post, Cyble urged users of Rockwell Automation, Hitachi Energy and Inaba Denki Sangyo, three industrial hardware providers, to patch critical vulnerabilities in their products.

The vulnerabilities affect various products, including Rockwell Automation Industrial Data Center, Hitachi Energy MicroSCADA Pro/X SYS600, and Inaba Denki Sangyo CHOCO TEI WATCHER mini-industrial cameras.

The identified vulnerabilities are:

  • CVE-2025-23120: A deserialization of untrusted data vulnerability in Veeam Backup and Replication, potentially allowing remote code execution to the Rockwell Automation Industrial Data Center (IDC) product range (CVSS v3.1 score: 9.9)
  • CVE-2025-25211: A weak password requirement vulnerability in Inaba Denki Sangyo CHOCO TEI WATCHER mini-industrial cameras, potentially allowing unauthorized access (CVSS v3.1 score: 9.8)
  • CVE-2025-26689: A forced browsing vulnerability in Inaba Denki Sangyo CHOCO TEI WATCHER mini-industrial cameras, potentially allowing data tampering and product setting modifications (CVSS v3.1 score: 9.8)
  • CVE-2024-4872: An improper neutralization of special elements in data query logic vulnerability in Hitachi Energy MicroSCADA Pro/X SYS600, potentially allowing code injection (CVSS v3.1 score: 8.8)
  • CVE-2024-3980: A path traversal vulnerability in Hitachi Energy MicroSCADA Pro/X SYS600, potentially allowing file system manipulation and session hijacking (CVSS v3.1 score: 8.8)

These are the most critical vulnerabilities identified in Cyble’s latest ICS Vulnerability Report, which examined 70 flaws in ICS, operational technology (OT) and supervisory control and data acquisition (SCADA) systems.

The vulnerabilities identified affect systems across five sectors, including critical manufacturing, energy, healthcare, wastewater and commercial facilities.

“Given the critical role of SCADA, DCS, and MES systems, immediate mitigation—including patching, authentication hardening, and access restrictions—is essential to prevent exploitation,” Cyble wrote.

Read now: Five ICS Security Challenges and How to Overcome Them

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cyble-urges-critical-vulnerability/