Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Error’d: Pickup Sticklers

      September 27, 2025

      From Prompt To Partner: Designing Your Custom AI Assistant

      September 27, 2025

      Microsoft unveils reimagined Marketplace for cloud solutions, AI apps, and more

      September 27, 2025

      Design Dialects: Breaking the Rules, Not the System

      September 27, 2025

      Building personal apps with open source and AI

      September 12, 2025

      What Can We Actually Do With corner-shape?

      September 12, 2025

      Craft, Clarity, and Care: The Story and Work of Mengchu Yao

      September 12, 2025

      Cailabs secures €57M to accelerate growth and industrial scale-up

      September 12, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Using phpinfo() to Debug Common and Not-so-Common PHP Errors and Warnings

      September 28, 2025
      Recent

      Using phpinfo() to Debug Common and Not-so-Common PHP Errors and Warnings

      September 28, 2025

      Mastering PHP File Uploads: A Guide to php.ini Settings and Code Examples

      September 28, 2025

      The first browser with JavaScript landed 30 years ago

      September 27, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured
      Recent
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»CISA Warns of Critical ICS Flaws in Siemens, Tigo Energy, and EG4 Equipment

    CISA Warns of Critical ICS Flaws in Siemens, Tigo Energy, and EG4 Equipment

    August 22, 2025

    CISA

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) have released four new Industrial Control Systems (ICS) advisories. These advisories expose multiple vulnerabilities in widely used ICS equipment from Siemens, Tigo Energy, and EG4 Electronics. 

    ICSA-25-231-01 and ICSA-25-231-02 focus on Siemens’ Desigo CC Product Family, SENTRON Powermanager, and Mendix SAML Module—critical components used across global industrial environments. 

    CISA’s advisory ICSA-25-231-01 details a vulnerability (CVE-2025-47809) involving the Wibu CodeMeter, a software licensing component used in Siemens Desigo CC and SENTRON Powermanager. With a CVSS v3.1 score of 8.2, this vulnerability stems from a Least Privilege Violation (CWE-272), where users could exploit Windows Explorer through the CodeMeter Control Center without requiring a system reboot or logoff post-installation. 

    All versions of Desigo CC (V5.0 to V8) and SENTRON Powermanager (V5 to V8) are affected. Siemens recommends updating to CodeMeter version 8.30a and restarting the system post-installation to mitigate the issue. Siemens first disclosed this vulnerability to CISA and has further information on its ProductCERT page. 

    Remote Exploitation in Mendix SAML Module 

    In ICSA-25-231-02, Siemens’ Mendix SAML module was found to contain an Improper Verification of Cryptographic Signature (CWE-347), which could allow unauthenticated attackers to hijack user accounts in specific Single Sign-On (SSO) configurations. 

    Tagged as CVE-2025-40758 and scoring 8.7 on CVSS v3.1, the vulnerability affects multiple Mendix SAML versions prior to V3.6.21 (for Mendix 9.24), V4.0.3 (Mendix 10.12), and V4.1.2 (Mendix 10.21). Siemens advises enabling encryption settings and updating the module. The issue primarily impacts the critical manufacturing sector and was also reported directly by Siemens to CISA. 

    Tigo Energy Cloud Connect Advanced Under Active Exploitation 

    ICSA-25-217-02 (Update A) highlights multiple high-risk vulnerabilities in Tigo Energy’s Cloud Connect Advanced (CCA) device, essential to solar energy management systems. 

    With a CVSS v4 base score of 9.3, the most critical vulnerability (CVE-2025-7768) involves the use of hard-coded credentials (CWE-798), which allows unauthorized access and administrative control. Other serious issues include: 

    • Command Injection (CVE-2025-7769, CWE-77) with a CVSS v3.1 score of 8.8, now confirmed to be publicly exploitable. 
    • Predictable Session IDs (CVE-2025-7770, CWE-337), enabling attackers to bypass authentication and access sensitive functions. 

    These flaws affect Cloud Connect Advanced versions 4.0.1 and earlier. Tigo Energy is actively developing patches and urges users to consult its Help Center for interim security recommendations. CISA advises isolating ICS networks, restricting internet access, and using VPNs with caution due to potential vulnerabilities. 

    EG4 Electronics Inverters Contain Multiple Security Risks 

    ICSA-25-219-07 (Update A) discloses critical flaws in EG4 Electronics’ inverter systems, used in residential and commercial solar installations worldwide. Vulnerabilities include: 

    • Cleartext Transmission of Sensitive Data (CVE-2025-52586, CWE-319) 
    • Download of Code Without Integrity Check (CVE-2025-53520, CWE-494) 
    • Observable Discrepancy (CVE-2025-47872, CWE-203) 
    • Improper Restriction of Authentication Attempts (CVE-2025-46414, CWE-307) 

    The CVSS v4 score reaches as high as 9.2, reflecting the severity of these flaws. Attackers could intercept unencrypted commands, install malicious firmware, perform brute-force attacks on PIN codes, or access configuration settings through insecure APIs. 

    These vulnerabilities affect all versions of the following models: 

    • EG4 12kPV, 18kPV, Flex 21, Flex 18 
    • EG4 6000XP, 12000XP 
    • EG4 GridBoss 

    EG4 has addressed some issues through server-side fixes, including standardizing registration endpoint responses and limiting authentication attempts. However, the company is still working on firmware and hardware solutions, with new hardware expected by October 15, 2025. 

    CISA Urges Action from ICS Operators 

    CISA stresses that ICS environments are increasingly targeted by cyber actors due to their critical role in infrastructure. While there have been no confirmed large-scale exploits linked to these specific vulnerabilities (except one now publicly known in Tigo’s case), CISA recommends the following mitigation strategies: 

    • Isolating ICS from internet-facing networks. 
    • Updating devices and software to the latest secure versions. 
    • Performing risk assessments prior to deploying mitigation strategies. 

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous Article70,000 WordPress Sites Exposed by Inspiro Theme Security Flaw
    Next Article Ex-Developer Jailed Four Years for Sabotaging Ohio Employer with Kill-Switch Malware

    Related Posts

    Development

    Using phpinfo() to Debug Common and Not-so-Common PHP Errors and Warnings

    September 28, 2025
    Development

    Mastering PHP File Uploads: A Guide to php.ini Settings and Code Examples

    September 28, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    The Last Run of Chandru

    Artificial Intelligence

    Announcing Gemma 3n preview: Powerful, efficient, mobile-first AI

    Artificial Intelligence

    LaunchDarkly adds new features to help developers release faster while mitigating risk

    Tech & Work

    AI-Driven Antitrust and Competition Law: Algorithmic Collusion, Self-Learning Pricing Tools, and Legal Challenges in the US and EU

    Machine Learning

    Highlights

    Hinex ST: Vanilla Powder Buy 400 gm Teen Online

    April 11, 2025

    Post Content Source: Read More 

    Molex Fiber Optic LIU Dealer in Delhi | 24 & 48 Port Loaded Panels

    May 7, 2025

    White House seeks 10% increase in cybersecurity spend

    April 9, 2025

    AI, Data Protection, and Governance: Key Pillars for the Future of Business

    April 1, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.