The Cybersecurity and Infrastructure Security Agency (CISA) has released two Industrial Control Systems (ICS) advisories today, addressing critical security vulnerabilities that could potentially impact multiple critical infrastructure sectors including healthcare, manufacturing, energy, transportation, and water systems.
The advisories, labeled ICSA-25-121-01 and ICSMA-25-121-01, provide crucial information about security issues, vulnerabilities, and potential exploits affecting KUNBUS GmbH Revolution Pi and MicroDicom DICOM Viewer, respectively.
These vulnerabilities identified could lead to significant operational disruptions if left unaddressed.
The first advisory (ICSA-25-121-01) addresses multiple vulnerabilities in KUNBUS GmbH’s Revolution Pi industrial automation system.
Among the most severe issues is CVE-2025-35996, which involves an authentication bypass vulnerability allowing potential attackers to gain unauthorized access.
Additionally, CISA identified CVE-2025-36558, categorized as CWE-97 (Improper Neutralization of Server-Side Includes Within a Web Page), which could permit cross-site scripting attacks if exploited.
According to the advisory, PiCtory version 2.11.1 and earlier are particularly vulnerable to these attacks.
KUNBUS has not yet released patches, leaving thousands of devices in water treatment plants, power distribution systems, and factory floors exposed.
Adam Bromiley of Pen Test Partners discovered and reported these vulnerabilities to CISA.
The second advisory (ICSMA-25-121-01) focuses on MicroDicom DICOM Viewer through version 2025.1 (Build 3321), which is extensively used in healthcare facilities for viewing medical imaging.
CISA identified two high-severity vulnerabilities: CVE-2025-35975 (Out-of-Bounds Write, CWE-787) and CVE-2025-36521 (Out-of-Bounds Read, CWE-125).
Both vulnerabilities could potentially allow attackers to execute arbitrary code by having users open specially crafted malicious DCM files.
“MicroDicom DICOM Viewer is vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code,” the advisory states.
Michael Heinzl reported these vulnerabilities to CISA. MicroDicom recommends users update to version 2025.2 or later to address these issues.
CISA’s recommended mitigations include minimizing network exposure for all control systems, locating control systems behind firewalls separate from business networks, using secure methods like VPNs when remote access is required, and implementing defense-in-depth strategies.
“CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures,” the agency noted.
As of this release, CISA reports that no known public exploitation specifically targeting these vulnerabilities has been observed.
System administrators and security professionals are strongly encouraged to review the complete advisories on CISA’s website for comprehensive technical details and implementation guidance for the recommended mitigations.
The agency continues to monitor these vulnerabilities and will provide updates if additional information becomes available.
Are you from the SOC and DFIR Teams? – Analyse Real time Malware Incidents with ANY.RUN -> Start Now for Free.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…