Industrial advisories tell you a vulnerability exists somewhere in the ecosystem. Finite State tells you whether it's inside your controller, which firmware builds carry it, and whether an attacker could reach it.

The Challenge
Advisories arrive daily from CISA, the NVD, and researchers. Each one raises the same question about a specific PLC firmware build, and answering it falls to the product security team.
Advisories name products. Your exposure lives in the components inside them.
The same controller ships in many configurations, each with a different component set.
Industrial disclosures keep climbing, and most have nothing to do with your portfolio.
Asset owners ask whether they're affected, and they expect an answer quickly.

Our Approach
The Product Security OS analyzes the firmware you ship, builds a component-level inventory from it, and correlates threat and exploit intelligence against that inventory. New disclosures map to specific products and builds automatically.
Product Context
Intelligence becomes actionable once it maps to an accurate inventory. Finite State derives a ground truth software inventory from firmware, binaries, source, and supplier artifacts, so a new disclosure resolves to named products and versions.
Across the portfolio
Derive component inventories directly from firmware and binaries
Reconcile generated inventories against supplier SBOMs
Trace a single component across products, versions, and builds
Tie every finding back to a specific artifact
Component data gets enriched from more than 200 vulnerability and exploit intelligence sources, then evaluated against the product itself.
CISA's Known Exploited Vulnerabilities catalog and confirmed exploitation signals.
Exploit prediction scoring and published proof-of-concept activity.
Whether the vulnerable code path can be reached in the build that shipped.
The affected version, interface, and configuration in the field.
The result is intelligence read against your product rather than in isolation.
Original Research
Finite State's research team analyzes real industrial firmware and publishes what it finds. In Rough Around the Edges, produced with Forescout Vedere Labs, we examined firmware from five OT and IoT router vendors.
Rough Around the Edges
Operational Impact
A disclosure is only actionable once you know which of your products it touches.
Enrichment and Coverage
Vulnerability and exploit intelligence sources
Of detected CVEs analyzed for reachability
To return reachability results on detected CVEs
Of analyzed findings confirmed unreachable since 2024
What Changes for Your Team
A named list of affected products. Disclosures arrive attached to the builds carrying the component.
Fewer false alarms. Reachability separates real exposure from code that only sits in the image.
Answers for asset owners. Customer questions get a determination with the analysis behind it.
FAQ
Related Resources
Threat intelligence connects to how you prioritize, how you respond, and what you can prove.
Bring one firmware image and we'll show you the components, the known vulnerabilities, and what's actually reachable.
© 2026 Finite State. All rights reserved.