CISA recently added two critical CVSS 9.8 vulnerabilities impacting Hikvision and Rockwell Automation to its Known Exploited Vulnerabilities (KEV) catalog. These flaws are being actively exploited, posing a high risk to industrial and enterprise environments.
Vulnerability Breakdown
- Hikvision (CVE-2017-7921): An Improper Authentication flaw in various IP cameras and recorders. It allows remote attackers to bypass authentication and gain full control of the device or access sensitive data.
- Rockwell Automation (CVE-2021-22681): A flaw involving Insufficiently Protected Credentials in Logix controllers and Studio 5000 software. Attackers can bypass cryptographic verification to remotely alter device configurations or program code.
Required Actions
- Remediation Deadline: Federal agencies must patch these vulnerabilities by March 26, 2026.
- Mitigation: Organizations should immediately apply the latest firmware updates.
- Hikvision Security Advisory
- Rockwell Automation Security Center