Siemens SIMATIC IoT2050 Advanced Missing Authentication Vulnerability
Siemens ProductCERT has published an advisory (SSA-834709) regarding a critical vulnerability in SIMATIC IoT2050 Advanced devices (6ES7647-0BA00-1YA2) running Industrial OS with Node-RED installed. The vulnerability, tracked as CVE-2026-58115, is due to missing authentication on the Node-RED HTTP interface, allowing unauthenticated remote attackers to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. The CVSS v3.1 base score is 10.0 (Critical). Affected versions are those prior to V4.3.4.1. Siemens recommends updating to V4.3.4.1 or later, and provides mitigations such as hardening the Node-RED installation or uninstalling Node-RED. The advisory was initially released on 2026-08-11 and republished by CISA on 2026-08-25. The vulnerability affects devices deployed worldwide, particularly in critical infrastructure sectors including Chemical, Critical Manufacturing, Energy, and Transportation Systems.
What we know
The vulnerability is CVE-2026-58115, a missing authentication issue in the Node-RED HTTP interface.
▤ 1 sources›
An unauthenticated remote attacker can create malicious flows and execute arbitrary code with maximum privileges.
▤ 1 sources›
The advisory was published by Siemens on 2026-08-11 and republished by CISA on 2026-08-25.
▤ 1 sources›
Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed are affected.
▤ 1 sources›
Siemens has released version V4.3.4.1 to fix the vulnerability.
▤ 1 sources›
Mitigations include hardening Node-RED installation or uninstalling Node-RED.
▤ 1 sources›
CVSS v3.1 base score is 10.0 (Critical).
▤ 1 sources›
Affected versions are prior to V4.3.4.1.
▤ 1 sources›
Open any source to inspect its original language, when DoseFix received it, and the claims it supports.
Siemens SIMATIC IoT2050 Advanced
cisa.gov · EN · Published · ReceivedLive reports
View allComments 0
Discuss this event in persistent threads. Live chat remains separate.
No comments yet. Start the conversation.