Desk live·
ForensicPost
Cloud/Infrastructure/File 22-0620

Forescout Catalogued 56 Insecure-by-Design Flaws Across 10 Industrial Vendors

Forescout’s OT:ICEFALL catalogued 56 vulnerabilities across 26 device models from ten industrial vendors, and grouped them under a heading the corpus keeps returning to: insecure by design. There is no patch for a design assumption.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetIndustrial control devices
ActorUnattributed
S. Rosler12 min readConfidence: high3 sources reviewed

On 20 June 2022 Forescout’s Vedere Labs published OT:ICEFALL, documenting 56 vulnerabilities affecting around 26 device models from ten operational technology vendors, among them Emerson, Honeywell, Motorola, Omron, Phoenix Contact, Siemens and Yokogawa.

The reported distribution was credential compromise 38%, firmware manipulation 21%, remote code execution 14% and configuration manipulation 8%. Of roughly 18 million devices the firm monitored, nearly 30,000 were reported vulnerable. CISA issued related advisories.

The Category Is The Contribution

Most vulnerability research finds mistakes — a bounds check missing, a parser confused. This set is largely not that. The devices behave as specified; the specification assumed the network was trustworthy.

Unauthenticated firmware update, unauthenticated configuration change, credentials sent in a form that can be replayed: each was a deliberate choice made when the controller sat on an isolated network with a physical door in front of it. We filed the same reasoning at 22-0922, where an API answered anyone, and at 22-0417 — a system doing what it was designed to do.

This Is The Precondition For The Water Files

We have recorded controllers being manipulated at 26-0727 and 26-0729, and a plant driven into a damaging state at 22-0627. Those files record consequences; this one records why the consequences were available.

A device that accepts a logic change from anyone who can reach it does not need to be exploited in the ordinary sense. It needs to be reached. That reframes the whole class: the security boundary is the network path, and once that is wrong the device offers no second line.

Numbering Them Does Not Fix Them

Assigning CVEs to design decisions creates a strange artefact — identifiers for things the vendor may consider correct behaviour, on equipment with service lives measured in decades.

We have recorded the same shape at 23-1010b, where the defect sat in a protocol rather than a product. Neither has a patch pipeline. The realistic answer in both cases is compensating controls the operator has to build and keep, which is why the guidance at 26-0728 tells operators to plan for degraded operation rather than for prevention.

How we reported this

Built on Forescout’s published OT:ICEFALL research and contemporaneous reporting of it. The 20 June 2022 publication, the 56 vulnerabilities across roughly 26 device models and ten vendors, the named vendors, the category percentages and the ~30,000 of 18 million monitored devices figure are as published by the researchers. The device population figure reflects that vendor’s own visibility and is not a market-wide measurement; it is carried as reported. No exploit detail, proof of concept or indicator is reproduced, and no individual CVE is enumerated here. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. OT:ICEFALL — 56 Vulnerabilities Caused by Insecure-by-Design Practices in OTForescout
  2. Researchers Disclose 56 Vulnerabilities Impacting OT Devices from 10 VendorsThe Hacker News
  3. Forescout discloses "OT:Icefall," 56 flaws from 10 vendorsTechTarget
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary