← Back to home
ICSA-25-296-03  ·  Published 2025-10-23  ·  View on CISA ICS-CERT ↗

Veeder-Root TLS4B Automatic Tank Gauge System

CVSS 9.9 CRITICAL

Risk Summary

Successful exploitation of these vulnerabilities could allow attackers to execute system-level commands, gain full shell access, achieve remote command execution, move laterally within the network, trigger a denial of service condition, cause administrative lockout, and disrupt core system functionalities.

Remediations

  • (CVE-2025-58428) Veeder-Root recommends users upgrade the TLS4B to Version 11.A.
  • Veeder-Root advises that their ASCs review and implement these best practices for network security with their users, when installing a new console or setting up a network port.
  • Contact Veeder-Root Technical Support at +1.800.323.1799 for additional help or questions.
  • (CVE-2025-55067) Veeder-Root is aware of the vulnerability and will provide a fix for it. Until a fix is available, users should adhere to the network security best practices provided by Veeder-Root. Additionally, users should make all efforts to protect the borders of their environment to prevent bad actors from infiltrating and causing this issue.

Affected Vendors

Veeder-Root

Affected Products (1)

Veeder-Root · TLS4B <11.A

Affected Sectors

Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more