On November 19, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a set of six Industrial Control Systems (ICS) advisories, flagging security vulnerabilities in products from three different vendors: Schneider Electric, Shelly, and METZ CONNECT. These advisories are crucial for organizations in critical infrastructure sectors that rely on these systems for process automation and control. The alerts cover products such as SCADA software and smart power management devices. While specific CVE details were not enumerated in the summary reports, CISA strongly advises asset owners to review the detailed advisories on their website and implement the provided mitigation guidance to secure their operational technology (OT) environments against potential cyber threats.
The release consists of six separate advisories. While the source material does not provide specific CVE numbers or technical descriptions, the advisories cover a range of potential security issues common in ICS environments, such as unauthenticated access, command injection, or buffer overflows.
The vulnerabilities impact products from the following vendors:
Schneider Electric (4 advisories):
EcoStruxure Machine SCADA ExpertPro-face BLUE Open StudioPowerChute Serial ShutdownEcoStruxure advisoryShelly (1 advisory):
Shelly Pro 4PMShelly Pro 3EMMETZ CONNECT (1 advisory):
METZ CONNECT EWIO2These products are used globally in various critical infrastructure and manufacturing settings for monitoring and controlling industrial processes.
The source articles do not mention whether these vulnerabilities are being actively exploited in the wild. However, vulnerabilities in ICS/OT systems are high-value targets for nation-state actors and sophisticated cybercriminals seeking to disrupt critical infrastructure.
Exploitation of vulnerabilities in ICS environments can have severe real-world consequences, including:
Since specific vulnerabilities are not detailed, detection should focus on general anomalous behavior in OT networks.
network_traffic_patternAnomalous OT protocol commandslog_sourceHMI/SCADA Application Logsprocess_nameAnomalous process on engineering workstationnetwork_traffic_patternIT-to-OT network trafficCISA urges all affected organizations to visit the official ICS advisories page for detailed mitigation steps. General best practices for ICS security include:
M1051 - Update Software).M1030 - Network Segmentation).M1026 - Privileged Account Management).Isolating the OT network from the IT network is the most critical architectural defense for ICS security.
Applying vendor-provided patches is essential, but must be done carefully after testing in a non-production environment.
Use application whitelisting on HMIs and engineering workstations to prevent unauthorized code from running.
Enforce strong password policies and avoid using shared accounts for engineers and operators.
CISA publishes six new ICS advisories.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.