ICSA-25-296-03
·
Published 2025-10-23
·
View on CISA ICS-CERT ↗
Veeder-Root TLS4B Automatic Tank Gauge System
CVSS 9.9
CRITICAL
Risk Summary
Successful exploitation of these vulnerabilities could allow attackers to execute system-level commands, gain full shell access, achieve remote command execution, move laterally within the network, trigger a denial of service condition, cause administrative lockout, and disrupt core system functionalities.
CVEs (2)
Remediations
- (CVE-2025-58428) Veeder-Root recommends users upgrade the TLS4B to Version 11.A.
- Veeder-Root advises that their ASCs review and implement these best practices for network security with their users, when installing a new console or setting up a network port.
- Contact Veeder-Root Technical Support at +1.800.323.1799 for additional help or questions.
- (CVE-2025-55067) Veeder-Root is aware of the vulnerability and will provide a fix for it. Until a fix is available, users should adhere to the network security best practices provided by Veeder-Root. Additionally, users should make all efforts to protect the borders of their environment to prevent bad actors from infiltrating and causing this issue.
Affected Vendors
Veeder-Root
Affected Products (1)
Veeder-Root
·
TLS4B
<11.A
Affected Sectors
Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more