Executive Summary
In October 2025, critical vulnerabilities were disclosed in the Veeder-Root TLS4B Automatic Tank Gauge System, widely deployed across the global energy sector. Security researcher Pedro Umbelino reported a severe command injection flaw (CVE-2025-58428) in the SOAP-based web service, enabling attackers with valid credentials to execute system-level commands, gain shell access, and potentially move laterally within targeted networks. A second vulnerability (CVE-2025-55067) affects time handling, potentially enabling attackers to cause authentication failures and denial of service by exploiting the Unix epoch rollover issue. Both vulnerabilities are remotely exploitable and threaten operational continuity, device functionality, and network integrity.
This incident highlights the growing exposure of industrial control systems to sophisticated, remotely exploitable vulnerabilities. With the energy sector’s increasing reliance on interconnected OT devices, attackers are targeting control interfaces and authentication flaws to achieve deeper network access, reinforcing the urgent need for proactive risk assessments and robust segmentation strategies.
Why This Matters Now
The Veeder-Root TLS4B vulnerabilities underscore urgent risks posed by insecure industrial control systems. These flaws enable full remote compromise and network movement, making critical infrastructure attractive targets for advanced threat actors. Immediate mitigation is vital, as similar attack methods are increasingly seen across OT environments, amplifying both operational disruption and compliance risks for global critical infrastructure.
Attack Path Analysis
An attacker with valid credentials exploited a command injection vulnerability in the TLS4B's SOAP interface to gain initial system access. This access enabled privilege escalation to shell-level control on the device. The attacker then moved laterally within the internal network to identify and potentially compromise adjacent systems. Using established footholds, the attacker set up command and control channels, possibly using unencrypted or covert traffic. Sensitive data or operational information could then be exfiltrated via outbound network paths. Finally, the attacker could trigger denial of service, administrative lockout, or disrupt operational functionality, impacting core system operations.
Kill Chain Progression
Initial Compromise
Description
Attacker exploited exposed SOAP web services using valid credentials to remotely execute commands on the ICS device.
Related CVEs
CVE-2025-58428
CVSS 9.9The TLS4B ATG system's SOAP-based interface allows remote attackers with valid credentials to execute system-level commands, potentially leading to full shell access and lateral network movement.
Affected Products:
Veeder-Root TLS4B Automatic Tank Gauge System – < 11.A
Exploit Status:
no public exploitCVE-2025-55067
CVSS 7.1The TLS4B ATG system improperly handles Unix time values beyond the 2038 epoch rollover, potentially causing authentication failures and disruption of core functionalities.
Affected Products:
Veeder-Root TLS4B Automatic Tank Gauge System – < 11.A
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Indirect Command Execution
Command and Scripting Interpreter: Unix Shell
Create or Modify System Process: Linux Service
Exploit Public-Facing Application
Modify Authentication Process
Valid Accounts
Exploitation of Remote Services
Endpoint Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Addressing Vulnerabilities for Public-Facing Web Applications
Control ID: 6.4.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
CISA ZTMM 2.0 – Identity and Access Management
Control ID: Identity Management - Authentication
NIS2 Directive – Risk Management and Security of Network/Information Systems
Control ID: Article 21(2) (a,d)
DORA (Digital Operational Resilience Act) – ICT Risk Management Requirements
Control ID: Article 8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Oil/Energy/Solar/Greentech
Critical infrastructure vulnerability in fuel tank gauge systems enables remote command injection and system compromise, disrupting operational technology across energy facilities worldwide.
Automotive
Gas station tank monitoring systems face command injection attacks allowing remote access to fuel management infrastructure, potentially disrupting supply chains and operations.
Transportation
Fleet fuel management and storage facilities using TLS4B systems vulnerable to remote exploitation, risking operational disruption and unauthorized system access.
Utilities
Industrial control system vulnerabilities in automated tank gauges threaten utility infrastructure security, enabling lateral movement and denial of service attacks.
Sources
- Veeder-Root TLS4B Automatic Tank Gauge Systemhttps://www.cisa.gov/news-events/ics-advisories/icsa-25-296-03Verified
- CVE-2025-58428 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-58428Verified
- CVE-2025-55067 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-55067Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
CNSF-aligned Zero Trust controls—such as segmentation, encrypted traffic enforcement, egress policy, and inline threat detection—would have blocked or detected attacker movement, limited access scope, and restricted exfiltration and system disruption even after initial compromise.
Control: Cloud Firewall (ACF)
Mitigation: Exposed interfaces would be protected against unauthorized or suspicious inbound access.
Control: Threat Detection & Anomaly Response
Mitigation: Escalation activities and abnormal shell usage would trigger detection or alert.
Control: Zero Trust Segmentation
Mitigation: Lateral movement beyond the initial device would be prevented or tightly restricted.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound traffic to C2 infrastructure would be blocked or flagged.
Control: Multicloud Visibility & Control
Mitigation: Data exfiltration routes would be visible and could be monitored or shut down.
Malicious command patterns and system attacks would be detected and blocked in real time.
Impact at a Glance
Affected Business Functions
- Fuel Monitoring
- Inventory Management
- Leak Detection
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of system configurations and operational data due to unauthorized access.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate ICS devices from broader network access and prevent lateral movement.
- • Deploy Cloud Firewall and egress filtering to strictly control inbound and outbound access to sensitive web interfaces and prevent unsanctioned C2 or exfiltration.
- • Enable inline threat detection and anomaly response to rapidly identify and respond to privilege escalation and post-compromise behavior.
- • Mandate encrypted traffic for all network communications to prevent credential theft and packet sniffing opportunities.
- • Centralize multicloud visibility and real-time monitoring to promptly detect and disrupt suspicious activities across the environment.



