CISA, as a coordinating national cybersecurity authority and CVE Numbering Authority, discloses vulnerabilities across a narrow set of industrial-control and software-assurance tools, including the Thorium parser and ICS protocol analyzers. Its disclosures skew strongly toward critical-severity outcomes, reflecting the safety-critical or foundational nature of the affected components and the serious consequences of memory corruption, input validation failures, and access-control flaws in industrial and secure-software contexts. Defenders should prioritize patching for CISA-disclosed vulnerabilities in ICS environments and secure-development toolchains; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cybersecurity and Infrastructure Security Agency (CISA) over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-35434CRITICAL CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could impersonate the Elasticsearch s | Sep 17, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-35433HIGH CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log in after a password re | Sep 17, 2025 | 8.8 | 27 | NO | NO |
CVE-2023-7244CRITICAL Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat
Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds
write in their primary analyses fun | Mar 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-7243CRITICAL
Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat
Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds
write while analyzing specific Eth | Mar 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-35436HIGH CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote attacker could cause a crash by providing a specially craft | Sep 17, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-35432HIGH CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker can send unlimited messages to a user who is pending verifi | Sep 17, 2025 | 7.5 | 24 | NO | NO |
CVE-2023-7242HIGH
Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat
Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds
read during the process of analyz | Mar 1, 2024 | 8.2 | 23 | NO | NO |
CVE-2025-35430MEDIUM CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated attacker could access arbitrary fi | Sep 17, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-67634MEDIUM The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to imp | Dec 12, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-35431MEDIUM CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify LDAP authorization data such as group memberships. Fixed in 1 | Sep 17, 2025 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cybersecurity and Infrastructure Security Agency (CISA).
Media articles that mention a CVE ID that affects a product developed by Cybersecurity and Infrastructure Security Agency (CISA) — matched by CVE ID, not by vendor name.