CISA Warns of Critical Security Flaws in Major Industrial Control Systems
Want more insights like this?
CISA issued 14 security advisories Tuesday highlighting serious vulnerabilities in industrial automation systems from Rockwell and ABB. The flaws affect critical manufacturing infrastructure, including Rockwell's ThinManager software, FactoryTalk platforms, and various controllers, plus ABB's ASPECT, NEXUS, and MATRIX equipment.
The most severe issues include authentication bypasses allowing attackers to take full device control, remote code execution vulnerabilities, and buffer overflows that could crash systems. One Rockwell ThinManager flaw (CVE-2025-9065) scores 8.6 on the severity scale, while ABB vulnerabilities reach 9.8.
Both companies have released patches and recommend immediate updates. CISA emphasizes these systems should never be directly exposed to the internet and must use proper network segmentation and VPN access controls.
Source: Industrial Cyber