Siemens SIMATIC IoT2050 Advanced
TL;DR
View CSAF Summary SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version. The following versions of Siemens SIMATIC IoT2050 Advanced are affected: SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) vers:intdot/<4.3.4.1 CVSS Vendor Equipment Vulnerabilities
v3 10 Siemens Siemens SIMATIC IoT2050 Advanced Missing Authentication for Critical Function
Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-58115 Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges. View CVE Details Affected Products Siemens SIMATIC IoT2050 Advanced Vendor: Siemens Product Version: SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) < V4.3.4.1 running Industrial OS with Node-RED installed Product Status: known_affected Remediations Mitigation Harden the Node-RED installation (see Node-RED User Guide) Mitigation Uninstall Node-RED Vendor fix Update to V4.3.4.1 or later version https://support.industry.siemens.com/cs/ww/en/view/109741799/ Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String
3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Ack
What Happened
Siemens SIMATIC IoT2050 Advanced, reported by CISA.
View CSAF Summary SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version. The following versions of Siemens SIMATIC IoT2050 Advanced are affected: SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) vers:intdot/<4.3.4.1 CVSS Vendor Equipment Vulnerabilities
v3 10 Siemens Siemens SIMATIC IoT2050 Advanced Missing Authentication for Critical Function
Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-58115 Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges. View CVE Details Affected Products Siemens SIMATIC IoT2050 Advanced Vendor: Siemens Product Version: SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) < V4.3.4.1 running Industrial OS with Node-RED installed Product Status: known_affected Remediations Mitigation Harden the Node-RED installation (see Node-RED User Guide) Mitigation Uninstall Node-RED Vendor fix Update to V4.3.4.1 or later version https://support.industry.siemens.com/cs/ww/en/view/109741799/ Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String
3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Ack
For the full technical details, see the original report.
Why It Matters for Businesses
This development could affect organizations that rely on the impacted technologies or services. Unpatched systems, misconfigured infrastructure, or lack of monitoring can leave businesses exposed to exploitation, data breaches, and regulatory penalties.
How to Check Your Exposure
Run a free scan on NEL Professional's Cyber Risk Scanner to check whether your domain is affected. The scan covers SSL/TLS, security headers, DNS configuration, email authentication, and more across 16 modules.
Mitigation Steps
- Patch immediately, Apply vendor patches or updates as soon as they are available.
- Review configurations, Check firewall rules, access controls, and security headers.
- Monitor logs, Watch for indicators of compromise (IOCs) related to this threat.
- Update security policies, Ensure incident response plans cover this type of threat.
- Run a security scan, Use automated tools to verify your exposure.
Need Expert Help?
If your organization needs help assessing or remediating this issue, hire a verified cybersecurity specialist through NEL Professionals.
Get up to 100 scans or unlimited lifetime access starting at $15.
View Plans →Comments (0)
No comments yet. Be the first to comment!
