Cyber Security News

CISA Releases ICS Advisories Targeting Vulnerabilities & Exploits

The Cybersecurity and Infrastructure Security Agency (CISA) has released two Industrial Control Systems (ICS) advisories today, addressing critical security vulnerabilities that could potentially impact multiple critical infrastructure sectors including healthcare, manufacturing, energy, transportation, and water systems.

The advisories, labeled ICSA-25-121-01 and ICSMA-25-121-01, provide crucial information about security issues, vulnerabilities, and potential exploits affecting KUNBUS GmbH Revolution Pi and MicroDicom DICOM Viewer, respectively. 

These vulnerabilities identified could lead to significant operational disruptions if left unaddressed.

KUNBUS Revolution Pi Vulnerabilities Expose Critical Infrastructure to Remote Exploitation

The first advisory (ICSA-25-121-01) addresses multiple vulnerabilities in KUNBUS GmbH’s Revolution Pi industrial automation system. 

Among the most severe issues is CVE-2025-35996, which involves an authentication bypass vulnerability allowing potential attackers to gain unauthorized access. 

Additionally, CISA identified CVE-2025-36558, categorized as CWE-97 (Improper Neutralization of Server-Side Includes Within a Web Page), which could permit cross-site scripting attacks if exploited.

According to the advisory, PiCtory version 2.11.1 and earlier are particularly vulnerable to these attacks. 

KUNBUS has not yet released patches, leaving thousands of devices in water treatment plants, power distribution systems, and factory floors exposed.

Adam Bromiley of Pen Test Partners discovered and reported these vulnerabilities to CISA. 

MicroDicom DICOM Viewer Flaws Threaten Healthcare Data Integrity

The second advisory (ICSMA-25-121-01) focuses on MicroDicom DICOM Viewer through version 2025.1 (Build 3321), which is extensively used in healthcare facilities for viewing medical imaging. 

CISA identified two high-severity vulnerabilities: CVE-2025-35975 (Out-of-Bounds Write, CWE-787) and CVE-2025-36521 (Out-of-Bounds Read, CWE-125). 

Both vulnerabilities could potentially allow attackers to execute arbitrary code by having users open specially crafted malicious DCM files.

“MicroDicom DICOM Viewer is vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code,” the advisory states. 

Michael Heinzl reported these vulnerabilities to CISA. MicroDicom recommends users update to version 2025.2 or later to address these issues.

CISA’s recommended mitigations include minimizing network exposure for all control systems, locating control systems behind firewalls separate from business networks, using secure methods like VPNs when remote access is required, and implementing defense-in-depth strategies.

“CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures,” the agency noted. 

As of this release, CISA reports that no known public exploitation specifically targeting these vulnerabilities has been observed.

System administrators and security professionals are strongly encouraged to review the complete advisories on CISA’s website for comprehensive technical details and implementation guidance for the recommended mitigations.

The agency continues to monitor these vulnerabilities and will provide updates if additional information becomes available.

Are you from the SOC and DFIR Teams? – Analyse Real time Malware Incidents with ANY.RUN -> Start Now for Free.

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago