Executive Summary
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) published 12 critical advisories detailing multiple vulnerabilities affecting industrial control systems (ICS) from major vendors including Johnson Controls, Siemens, and Varex Imaging. These advisories highlight flaws exposed by threat assessments in device firmware, authentication mechanisms, remote access features, and legacy software within widely deployed ICS/OT products. An exploitation of these vulnerabilities could give adversaries access to critical operations, enable lateral movement within secure networks, or disrupt essential physical processes that underpin energy, healthcare, and manufacturing sectors.
The occurrence underscores the ongoing risks posed by legacy and unpatched OT technology in critical infrastructure. A surge in targeted attacks against ICS environments, evolving regulatory requirements, and new threat intelligence guidance are elevating urgency for rapid remediation, modern zero trust approaches, and the adoption of robust segmentation and visibility controls.
Why This Matters Now
This incident illustrates the persistent exposure of operational technology environments to cyber risk, as attackers increasingly exploit ICS/OT vulnerabilities to target infrastructure. With heightened adversary interest, regulatory scrutiny, and ransomware pivoting toward ICS, immediate attention is needed to patch vulnerabilities and reinforce architectural defenses in critical sectors.
Attack Path Analysis
Attackers exploited unpatched ICS/OT vulnerabilities to gain initial access to industrial systems. They leveraged misconfigurations or insufficient privilege controls to escalate their privileges within key infrastructure environments. Using east-west connectivity, the threat actors moved laterally across workloads or regions to reach critical systems. Once established, command and control channels were set up over the network to maintain persistence and coordinate actions. Sensitive ICS/OT configuration data or operational files were exfiltrated using covert outbound channels. Ultimately, attackers caused physical or business process disruption by manipulating or disabling control functions.
Kill Chain Progression
Initial Compromise
Description
Adversaries exploited exposed or vulnerable ICS/OT components (e.g., unpatched Johnson Controls, Siemens, or OpenPLC software) to gain initial network access.
Related CVEs
CVE-2024-32752
CVSS 7.5Insecure communications in Johnson Controls iSTAR Configuration Utility (ICU) may allow unauthorized access.
Affected Products:
Johnson Controls iSTAR Pro – All versions
Johnson Controls iSTAR Edge – All versions
Johnson Controls iSTAR eX – All versions
Johnson Controls iSTAR Ultra – Versions prior to 6.6.B
Johnson Controls iSTAR Ultra LT – Versions prior to 6.6.B
Johnson Controls ICU – All versions
Exploit Status:
no public exploitCVE-2025-26383
CVSS 6.5Memory leak in Johnson Controls iSTAR Configuration Utility (ICU) could expose unauthorized data from the host PC.
Affected Products:
Johnson Controls ICU – Versions prior to 6.9.5
Exploit Status:
no public exploitCVE-2025-26382
CVSS 7.8Buffer overflow in Johnson Controls iSTAR Configuration Utility (ICU) may lead to arbitrary code execution.
Affected Products:
Johnson Controls ICU – Versions prior to 6.9.5
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Remote System Discovery
Impact
Modify Control Logic
Impair Process Control
Monitor Process State
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIS2 Directive – Vulnerability Handling and Disclosure
Control ID: Article 21(2)(d)
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: Section 500.03
PCI DSS 4.0 – Security of System Components
Control ID: 6.3.3
CISA Zero Trust Maturity Model 2.0 – Asset Visibility and Vulnerability Management
Control ID: Asset Management Tier 1–2
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Article 8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Critical infrastructure vulnerabilities in Siemens energy systems and grid management platforms expose power generation and distribution networks to operational disruption.
Oil/Energy/Solar/Greentech
Industrial control system vulnerabilities in energy services and grid infrastructure threaten renewable energy operations and traditional energy production facilities.
Health Care / Life Sciences
Medical imaging vulnerabilities in Varex dental software and DICOM systems compromise patient data security and diagnostic equipment operational integrity.
Government Administration
CISA advisory highlights critical infrastructure protection gaps requiring immediate remediation across federal facilities utilizing affected Siemens and Johnson Controls systems.
Sources
- CISA Releases 12 Industrial Control Systems Advisorieshttps://www.cisa.gov/news-events/alerts/2025/12/11/cisa-releases-12-industrial-control-systems-advisoriesVerified
- Product Security Advisory JCI-PSA-2024-06-v2https://www.johnsoncontrols.com/-/media/project/jci-global/johnson-controls/us-region/united-states-johnson-controls/cyber-solutions/security-advisories/documents/jci-psa-2024-06-v2.pdfVerified
- Product Security Advisory JCI-PSA-2025-06https://www.johnsoncontrols.com/-/media/project/jci-global/johnson-controls/us-region/united-states-johnson-controls/cyber-solutions/security-advisories/documents/jci-psa-2025-06.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, encrypted traffic, robust egress controls, and real-time anomaly detection would have greatly restricted attacker movement, denied covert exfiltration, and reduced incident operational impact in ICS/OT cloud environments.
Control: Cloud Firewall (ACF)
Mitigation: Blocked unauthorized inbound access to critical ICS/OT workloads.
Control: Zero Trust Segmentation
Mitigation: Limited attacker's ability to reach privileged systems beyond initial breach.
Control: East-West Traffic Security
Mitigation: Detected and blocked unauthorized internal pivoting attempts.
Control: Egress Security & Policy Enforcement
Mitigation: Prevented unauthorized outbound channels used for command and control.
Control: Encrypted Traffic (HPE) & Inline IPS (Suricata)
Mitigation: Detected, blocked, or visibility into data exfiltration attempts.
Rapid detection and automated response to destructive activity.
Impact at a Glance
Affected Business Functions
- Physical Security Management
- Access Control Systems
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive access control configurations and unauthorized access to physical security systems.
Recommended Actions
Key Takeaways & Next Steps
- • Prioritize Zero Trust microsegmentation to isolate ICS/OT cloud workloads and prevent lateral movement.
- • Enforce strict egress filtering and leverage inline IPS for all outbound ICS/OT cloud traffic to detect exfiltration and C2 activity.
- • Deploy distributed cloud firewalls to control exposure of unpatched or legacy control systems at all perimeters.
- • Implement continuous anomaly detection with real-time alerting for unusual behavior across all ICS/OT network layers.
- • Mandate encrypted traffic for all data-in-motion, including east-west flows, to defend against packet sniffing and integrity breaches.



