Full Report
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued four new industrial control system (ICS) advisories, warning... The post CISA warns of critical ICS vulnerabilities in Siemens, LS Electric, Fuji, Dover infrastructure equipment appeared first on Industrial Cyber.
Analysis Summary
# Vulnerability: Multiple Critical ICS Vulnerabilities Affecting Siemens, LS Electric, Fuji Electric, and Dover Fueling
## CVE Details
- CVE ID: CVE-2025-40592 (Siemens)
- CVSS Score: 6.1 (Medium) [CVSS v3.1] / 4.6 [CVSS v4]
- CWE: Path Traversal (Implied by description)
- CVE ID: CVE-2025-49850 (LS Electric)
- CVSS Score: 7.8 (High) [CVSS v3.1] / 8.4 [CVSS v4]
- CWE: Out-of-Bounds Write (Implied)
- CVE ID: CVE-2025-49849 (LS Electric)
- CVSS Score: 7.8 (High) [CVSS v3.1] / 8.4 [CVSS v4]
- CWE: Out-of-Bounds Read (Implied)
- CVE ID: CVE-2025-49848 (LS Electric)
- CVSS Score: 7.8 (High) [CVSS v3.1] / 8.4 [CVSS v4]
- CWE: Heap-based Buffer Overflow (Implied)
- CVE ID: CVE-2025-32412 (Fuji Electric)
- CVSS Score: 7.8 (High) [CVSS v3.1] / [CVSS v4 Score Unavailable]
- CWE: Out-of-bounds Read (Implied)
- CVE ID: CVE-2025-41413 (Fuji Electric)
- CVSS Score: 7.8 (High) [CVSS v3.1] / 8.4 [CVSS v4]
- CWE: Out-of-bounds Write (Implied)
- CVE ID: CVE-2025-41388 (Fuji Electric)
- CVSS Score: 7.8 (High) [CVSS v3.1] / 8.4 [CVSS v4]
- CWE: Stack-based Buffer Overflow (Implied)
- CVE ID: CVE-2025-5310 (Dover Fueling)
- CVSS Score: 9.8 (Critical) [CVSS v3.0] / 9.2 [CVSS v4]
- CWE: Missing Authentication for Critical Function (CWE-287)
## Affected Systems
- Products: Siemens Mendix Studio Pro development environment
- Versions: Mendix Studio Pro 8 (Earlier than V8.18.35), V9 (Earlier than V9.24.35), V10 (Earlier than V10.23.0, or earlier than V10.6.24, V10.12.17, V10.18.7 for specific sub-versions), All versions of Mendix Studio Pro 11.
- Configurations: Related to module installation process.
- Products: LS Electric GMWin 4 programming software
- Versions: Version 4.18.
- Configurations: Requires parsing of PRJ files. (Note: Product is discontinued.)
- Products: Fuji Electric Smart Editor hardware
- Versions: Versions 1.0.1.0 and prior.
- Products: Dover Fueling Solutions ProGauge MagLink LX consoles (MagLink LX 4, MagLink LX Plus, MagLink LX Ultimate)
- Versions: MagLink LX 4/Plus earlier than 4.20.3; MagLink LX Ultimate earlier than 5.20.3.
- Configurations: Related to an exposed, undocumented, unauthenticated Target Communication Framework (TCF) interface.
## Vulnerability Description
**Siemens Mendix Studio Pro (CVE-2025-40592):** A path traversal vulnerability exists in the module installation process. Crafting a malicious module allows an attacker to write or modify arbitrary files outside the developer’s project directory upon module installation.
**LS Electric GMWin 4 (CVE-2025-49850, 49849, 49848):** Multiple memory corruption vulnerabilities (Out-of-bounds Write, Out-of-bounds Read, Heap-based Buffer Overflow) exist within the parsing of PRJ files due to insufficient validation of user-supplied data. This can lead to arbitrary code execution or unauthorized data access.
**Fuji Electric Smart Editor (CVE-2025-32412, 41413, 41388):** Multiple memory corruption vulnerabilities (Out-of-bounds Read, Out-of-bounds Write, Stack-based Buffer Overflow) exist, potentially allowing an attacker to execute arbitrary code.
**Dover Fueling Solutions ProGauge MagLink LX (CVE-2025-5310):** Missing authentication for a critical function exists via an undocumented, unauthenticated TCF interface exposed on a specific port. Successful exploitation allows an attacker to gain control of the monitoring device, manipulate fueling operations, delete configurations, or deploy malware.
## Exploitation
- Status: PoC available (Implied for Siemens path traversal via Marketplace distribution; Exploitable due to unauthenticated access for Dover Fueling)
- Complexity: Low/Medium (Varies by vulnerability; Dover Fueling appears low due to unauthenticated network access)
- Attack Vector: Network (Implied for Siemens distribution, LS Electric file parsing, Dover Fueling TCF interface), Adjacent (Possible for file sharing scenarios)
## Impact
- Confidentiality: High (LS Electric R/O, Dover Fueling config access)
- Integrity: High (Siemens arbitrary file write, LS Electric code execution, Dover Fueling config manipulation/malware deployment)
- Availability: Medium/High (Dover Fueling system manipulation)
## Remediation
### Patches
- **Siemens Mendix Studio Pro:**
- Version 8: Update to 8.18.35 or later.
- Version 9: Update to 9.24.35 or later.
- Version 10: Update to 10.23.0 or newer.
- Version 10 Sub-versions: 10.6 to 10.6.24 or later; 10.12 to 10.12.17 or later; 10.18 to 10.18.7 or later.
- Version 11: Fix not yet available.
- **LS Electric GMWin 4:** Discontinued. Users should migrate to the XGT series replacement.
- **Fuji Electric Smart Editor:** Update to Smart Editor v1.0.2.0 or later.
- **Dover Fueling Solutions:**
- MagLink LX 4/Plus: Update to version 4.20.3 or later.
- MagLink LX Ultimate: Update to version 5.20.3 or later.
### Workarounds
- **Siemens Mendix Studio Pro V11:** Apply interim countermeasures where possible until a fix is released.
- **Dover Fueling Solutions:** Secure or firewall access to the unauthenticated TCF interface, if possible, as an interim measure.
## Detection
- **Siemens:** Monitor module installation processes for suspicious file creation/modification outside expected project directories.
- **LS Electric/Fuji Electric:** Monitor ICS asset network traffic for file input containing malicious PRJ files or abnormal process behavior indicative of memory corruption.
- **Dover Fueling:** Monitor network interfaces for unauthorized connection attempts or data exchange patterns on the TCF port (undocumented). Look for attempts to create/delete files on the ProGauge consoles or system configuration changes.
## References
- [CISA Advisory ICSA-25-168-01 (Siemens)](https://www.cisa.gov/news-events/ics-advisories/icsa-25-168-01)
- [CISA Advisory ICSA-25-168-02 (LS Electric)](https://www.cisa.gov/news-events/ics-advisories/icsa-25-168-02)
- [CISA Advisory ICSA-25-168-04 (Fuji Electric)](https://www.cisa.gov/news-events/ics-advisories/icsa-25-168-04)
- [CISA Advisory ICSA-25-168-05 (Dover Fueling)](https://www.cisa.gov/news-events/ics-advisories/icsa-25-168-05)
- [Fuji Electric Patch Link (Defanged)](https://felib.fujielectric.co.jp/en/document_search?tab=software&document1%5B1%5D=M10009&document2%5B1%5D=M20104&product1%5B1%5D=P10003&product2%5B1%5D=P20023&product3%5B1%5D=P30623&product4%5B1%5D=S11132&discontinued%5B1%5D=0&count=20&sort=en_title&page=1®ion=en-glb)
- [LS Electric Replacement Product Link (Defanged)](https://www.ls-electric.com/products/category/Smart_Automation_Solution/PLC/XGT_Series_-*XGK,_XGI,_XGR*-)