Executive Summary
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released five separate advisories detailing multiple vulnerabilities discovered across widely deployed industrial control systems (ICS) products, including platforms from Industrial Video & Control, Iskra, Mirion Medical, and Mitsubishi Electric. These vulnerabilities range from improper authentication and unencrypted data flows to weak access controls and, if left unmitigated, could enable threat actors to compromise critical infrastructure, hijack remote operations, or disrupt medical and industrial processes. The affected organizations were notified, and remediation guidance was provided to reduce risk and limit exploitation by sophisticated actors.
This disclosure underscores an ongoing trend of vulnerability discoveries in ICS environments, where legacy protocols, insufficient segmentation, and growing connectivity increasingly expose operational networks to targeted attacks. Continued disclosures by agencies like CISA emphasize the urgent need for robust visibility, segmentation, and zero trust architectures in protecting critical infrastructure.
Why This Matters Now
Industrial control systems underpin critical sectors like energy, manufacturing, and healthcare—and newly discovered vulnerabilities allow attackers to target operational technology networks that once were considered isolated. With ransomware and nation-state threats sharply focused on ICS/OT, organizations must act quickly to address exposed gaps before they are exploited in the wild.
Attack Path Analysis
Attackers exploited unpatched ICS vulnerabilities to gain initial foothold in critical systems. Using privilege escalation techniques, they obtained higher-level access, possibly through credential abuse or abuse of misconfigurations. The adversary then moved laterally across internal ICS networks, leveraging insecure internal traffic and weak segmentation. Command and control was established via covert outbound channels or compromised remote access tools. Sensitive ICS data and system configurations were exfiltrated through unsecured or insufficiently monitored outbound paths. Finally, attackers had the potential to disrupt processes or deploy ransomware, causing operational and business impact.
Kill Chain Progression
Initial Compromise
Description
Adversaries exploited publicly disclosed ICS vulnerabilities to gain unauthorized entry into the operational network.
Related CVEs
CVE-2025-13510
CVSS 9.3A missing authentication vulnerability in Iskra iHUB and iHUB Lite allows remote attackers to manipulate system settings without authentication.
Affected Products:
Iskra iHUB – All versions
Iskra iHUB Lite – All versions
Exploit Status:
no public exploitCVE-2025-13658
CVSS 9.3A code injection vulnerability in Industrial Video & Control Longwatch allows unauthenticated remote attackers to execute arbitrary code via unprotected HTTP GET requests.
Affected Products:
Industrial Video & Control Longwatch – 6.309 to 6.334
Exploit Status:
no public exploitCVE-2025-13659
CVSS 7.8A vulnerability in Mirion Medical EC2 Software NMIS BioDose allows attackers to manipulate executable files, potentially leading to unauthorized code execution.
Affected Products:
Mirion Medical EC2 Software NMIS BioDose – V23.0 and prior
Exploit Status:
no public exploitCVE-2025-13660
CVSS 7.5A vulnerability in Mitsubishi Electric CNC Series could allow unauthorized access to system functions, leading to potential data manipulation or disruption.
Affected Products:
Mitsubishi Electric CNC Series – All versions
Exploit Status:
no public exploitCVE-2025-13661
CVSS 7.5A vulnerability in Mitsubishi Electric MELSEC iQ-R Series/iQ-F Series could allow unauthorized access to system functions, leading to potential data manipulation or disruption.
Affected Products:
Mitsubishi Electric MELSEC iQ-R Series – All versions
Mitsubishi Electric MELSEC iQ-F Series – All versions
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Remote System Discovery
Input Capture
Drive-by Compromise
Modify Controller Tasking
Impair Process Control
Service Stop
Valid Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security Vulnerabilities Identification
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 9
CISA ZTMM 2.0 – Continuous Threat & Vulnerability Identification
Control ID: Threat & Vulnerability Management.1
NIS2 Directive – Risk Management Measures
Control ID: Article 21(2)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Industrial Automation
Critical vulnerability exposure in ICS systems requires immediate patching of Mitsubishi Electric CNC and MELSEC controllers used extensively in manufacturing automation environments.
Oil/Energy/Solar/Greentech
Power generation and distribution facilities using affected ICS components face operational disruption risks from unpatched vulnerabilities in critical infrastructure control systems.
Health Care / Life Sciences
Medical device vulnerabilities in Mirion Medical EC2 Software create patient safety risks requiring urgent compliance review under HIPAA regulatory frameworks.
Utilities
Water treatment and electrical grid operators must assess exposure to compromised Iskra iHUB systems and Industrial Video Control platforms for operational continuity.
Sources
- CISA Releases Five Industrial Control Systems Advisorieshttps://www.cisa.gov/news-events/alerts/2025/12/02/cisa-releases-five-industrial-control-systems-advisoriesVerified
- Industrial Control Systems: Iskra iHUB Remains Without Security Patch for Nowhttps://www.heise.de/en/news/Industrial-Control-Systems-Iskra-iHUB-Remains-Without-Security-Patch-for-Now-11101110.htmlVerified
- CISA Issues Five New ICS Advisories on Emerging Vulnerabilities and Exploitshttps://gbhackers.com/five-new-ics-advisories/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing CNSF controls such as zero trust segmentation, east-west traffic security, and egress policy enforcement would have hindered attacker movement, C2 communications, and exfiltration attempts. Enhanced visibility, anomaly detection, and in-line IPS could enable organizations to detect, prevent, and contain each stage of the attack sequence.
Control: Inline IPS (Suricata)
Mitigation: Real-time detection and prevention of exploit attempts.
Control: Zero Trust Segmentation
Mitigation: Prevention of unauthorized lateral privilege escalation.
Control: East-West Traffic Security
Mitigation: Detection and blocking of unauthorized internal movements.
Control: Egress Security & Policy Enforcement
Mitigation: Disruption of outbound malicious communication.
Control: Cloud Firewall (ACF)
Mitigation: Prevention of unauthorized data exfiltration.
Early detection and containment of disruptive actions.
Impact at a Glance
Affected Business Functions
- Energy Management
- Water Treatment
- Medical Data Processing
- Manufacturing Operations
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive operational data, including energy consumption metrics, water treatment parameters, medical dosage information, and manufacturing process details.
Recommended Actions
Key Takeaways & Next Steps
- • Segregate ICS and operational zones with zero trust segmentation to prevent broad attacker movement.
- • Deploy inline IPS and anomaly detection to rapidly block exploits and detect suspicious activity at all network layers.
- • Enforce east-west and egress traffic controls to limit lateral movement and stop data exfiltration.
- • Continuously monitor, baseline, and log all privileged access and policy changes across multi-cloud and on-prem environments.
- • Regularly update and test incident response playbooks to ensure coverage for emerging ICS vulnerabilities and cloud-native attack vectors.



