HomeSecurityCISA warns of vulnerabilities in Consilium Fire Panel

CISA warns of vulnerabilities in Consilium Fire Panel

CISA has issued a critical warning for two serious security vulnerabilities affecting all versions of the Consilium Safety CS5000 Fire Panel, a widely used industrial control system used in fire safety environments worldwide.

See also: CISA warns of suspected broader SaaS attacks

Consilium vulnerabilities

These vulnerabilities, which were identified by cybersecurity researcher Andrew Tierney of Pen Test Partners, could allow remote attackers to gain privileged access and potentially render firewall systems inoperable, creating serious risks to critical infrastructure.

The first vulnerability, codenamed CVE-2025-41438, concerns the initialization of a resource with an insecure default configuration (CWE-1188). Specifically, there is a highly privileged account preinstalled on all CS5000that remains unchanged in production environments across many installations.

Although this account does not have root-level access, it has sufficient privileges to cause a serious disruption to the operation of the Fire Panel. This Consilium vulnerability has received a CVSS version 3.1 base score of 9.8 and a CVSS version 4 score of 9.3, with the vector string (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

The second vulnerability, with identifier CVE-2025-46352, results from hard-coded credentials (CWE-798) located in a VNC.

The password is visible as a string in the executable file that launches the VNC server and cannot be modified by users. Anyone who knows this embedded password can gain full remote access to the Fire Panel system. This vulnerability has also been rated as critical, receiving the same high CVSS scores: 9.8 (v3.1) and 9.3 (v4).

See also: CISA: Commvault vulnerability is being actively exploited

The Fire Panel CS5000 has been installed in many critical infrastructure sectors, such as commercial facilities, energy infrastructure, government agencies and buildings, healthcare and public health units, and transportation systems.

CISA warns of vulnerabilities in Consilium Fire Panel

The Consilium system, which is manufactured in Sweden, is installed worldwide, making the impact of the vulnerabilities particularly widespread.

Successful exploitation of the vulnerabilities could allow attackers to remotely control fire panels and potentially render them inoperable, creating serious security risks in critical environments where fire detection and suppression systems are essential.

Tierney, who first identified the issues in 2020, noted that the disclosure process took a long time due to challenges in initial communication with the manufacturer. The vulnerabilities were confirmed in multiple shipboard installations, demonstrating that the issues are common across all implementations of the CS5000 system.

See also: CISA: Broadcom Fabric OS, CommVault, Active! vulnerabilities in KEV Catalog

A relevant and important point that emerges from the above is the need for regular security audits and review of default settings in industrial systems , especially when they involve critical infrastructure such as fire safety. This incident could be used as a case study for organizations and security professionals .

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS