DoseFix LIVE
0votes
Security·Germany·CONFIRMED

Siemens SIMATIC IoT2050 Advanced Missing Authentication Vulnerability

Germany·

Siemens ProductCERT has published an advisory (SSA-834709) regarding a critical vulnerability in SIMATIC IoT2050 Advanced devices (6ES7647-0BA00-1YA2) running Industrial OS with Node-RED installed. The vulnerability, tracked as CVE-2026-58115, is due to missing authentication on the Node-RED HTTP interface, allowing unauthenticated remote attackers to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. The CVSS v3.1 base score is 10.0 (Critical). Affected versions are those prior to V4.3.4.1. Siemens recommends updating to V4.3.4.1 or later, and provides mitigations such as hardening the Node-RED installation or uninstalling Node-RED. The advisory was initially released on 2026-08-11 and republished by CISA on 2026-08-25. The vulnerability affects devices deployed worldwide, particularly in critical infrastructure sectors including Chemical, Critical Manufacturing, Energy, and Transportation Systems.

1 sources
Germany

What we know

The vulnerability is CVE-2026-58115, a missing authentication issue in the Node-RED HTTP interface.

1 sources

An unauthenticated remote attacker can create malicious flows and execute arbitrary code with maximum privileges.

1 sources

The advisory was published by Siemens on 2026-08-11 and republished by CISA on 2026-08-25.

1 sources

Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed are affected.

1 sources

Siemens has released version V4.3.4.1 to fix the vulnerability.

1 sources

Mitigations include hardening Node-RED installation or uninstalling Node-RED.

1 sources

CVSS v3.1 base score is 10.0 (Critical).

1 sources

Affected versions are prior to V4.3.4.1.

1 sources
Timeline of Siemens SIMATIC IoT2050 Advanced Vulnerability

Siemens has disclosed a critical missing authentication vulnerability (CVE-2026-58115) in SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed. An unauthenticated remote attacker could exploit this to execute arbitrary code with maximum privileges. Siemens has released a fix in version V4.3.4.1.

Verified · 1 sources

Live reports

View all
Timeline of Siemens SIMATIC IoT2050 Advanced VulnerabilityLocal voice · Germany
Verified

Comments 0

Discuss this event in persistent threads. Live chat remains separate.

Keep discussion civil and distinguish opinion from verified information.

No comments yet. Start the conversation.

Siemens SIMATIC IoT2050 Advanced Missing Authentication Vulnerability | DoseFix