Full Report
Rockwell Automation, Hitachi Energy and Inaba Denki Sangyo have products affected by critical vulnerabilities carrying severity ratings as high as 9.9
Analysis Summary
This summary is based on the analysis of the provided article detailing critical vulnerabilities affecting Industrial Control Systems (ICS) reported by Cyble.
# Vulnerability: Critical ICS Flaws Affecting Rockwell, Hitachi Energy, and Inaba Denki Products
## CVE Details
The article identifies multiple vulnerabilities:
- **CVE-2025-23120**:
- **CVSS Score**: 9.9 (Critical)
- **CWE**: Deserialization of Untrusted Data
- **CVE-2025-25211**:
- **CVSS Score**: 9.8 (Critical)
- **CWE**: Weak Password Requirements
- **CVE-2025-26689**:
- **CVSS Score**: 9.8 (Critical)
- **CWE**: Forced Browsing
- **CVE-2024-4872**:
- **CVSS Score**: 8.8 (High)
- **CWE**: Improper Neutralization of Special Elements in Data Query Logic (Code Injection)
- **CVE-2024-3980**:
- **CVSS Score**: *[Severity not explicitly stated in snippet, but path traversal implies high risk]*
- **CWE**: Path Traversal
## Affected Systems
- **Products**:
- Rockwell Automation Industrial Data Center (IDC) product range
- Hitachi Energy MicroSCADA Pro/X SYS600
- Inaba Denki Sangyo CHOCO TEI WATCHER mini-industrial cameras
- Veeam Backup and Replication (Mentioned as the source context for CVE-2025-23120)
- **Versions**: Specific vulnerable versions are not detailed in the snippet, but users of the listed products are urged to patch.
- **Configurations**: Not specified beyond the product type (ICS/SCADA devices).
## Vulnerability Description
The vulnerabilities span several high-impact flaws across different industrial vendors:
1. **CVE-2025-23120 (Rockwell IDC)**: A Deserialization of Untrusted Data issue, originating potentially from Veeam Backup and Replication integration, leading to Remote Code Execution (RCE).
2. **CVE-2025-25211 (Inaba CHOCO TEI WATCHER)**: A weak password requirement vulnerability allowing unauthorized access.
3. **CVE-2025-26689 (Inaba CHOCO TEI WATCHER)**: A Forced Browsing flaw enabling attackers to tamper with data and modify product settings.
4. **CVE-2024-4872 (Hitachi Energy MicroSCADA Pro/X SYS600)**: An improper neutralization vulnerability that can lead to Code Injection.
5. **CVE-2024-3980 (Hitachi Energy)**: A Path Traversal vulnerability.
## Exploitation
- **Status**: The article suggests Cyble *urged* immediate fixes, indicating these are critical flaws that warrant immediate attention, but does not explicitly confirm if they are currently exploited in the wild. Given the high scores, the risk is severe.
- **Complexity**: Likely **Medium** to **Low** for RCE/Injection flaws (CVE-2025-23120, CVE-2024-4872). Weak password and forced browsing issues (CVE-2025-25211, CVE-2025-26689) are generally **Low** complexity if authentication is bypassed or simple URL manipulation is sufficient.
- **Attack Vector**: Primarily **Network** (implied for RCE/Injection in ICS systems) or **Adjacent**.
## Impact
- **Confidentiality**: High (Potential unauthorized data access/disclosure via injection or unauthorized access).
- **Integrity**: High (Potential data tampering, configuration modification, or code execution).
- **Availability**: High (Potential loss of control or system shutdown via RCE or command injection).
## Remediation
### Patches
The article heavily implies that patches are available from the respective vendors (Rockwell Automation, Hitachi Energy, Inaba Denki Sangyo) and urges users to apply them. Specific patch versions are not listed in this summary snippet.
### Workarounds
No specific workarounds are detailed in the provided text.
## Detection
- **Indicators of Compromise**: IOCs are not provided in the summary. General IOCs would include abnormal outbound network connections from ICS devices, unexpected changes in system configurations, or execution of unexpected processes.
- **Detection methods and tools**: Standard network monitoring tools and IDS/IPS configured to look for anomalous traffic patterns targeted at vulnerable ICS protocols should be utilized. Vendors' security advisories should contain specific detection signatures.
## References
- Vendor Advisories: Rockwell Automation, Hitachi Energy, Inaba Denki Sangyo.
- Cyble Blog Post: hxxps://cyble[.]com/blog/ics-vulnerability-report-energy-cyble/
- Source Article: hxxps://www[.]infosecurity-magazine[.]com/news/cyble-urges-critical-vulnerability/