Siemens SIDIS Secured SmartPlug
View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version. The following versions of Siemens SIDIS Secured SmartPlug are affected: SIDIS Secured SmartPlug vers:intdot/<7.26.0310 CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens SIDIS Secured SmartPlug Improper Enforcement of Message Integrity During Transmission in a Communication Channel, Reusing a Nonce, Key Pair in Encryption, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Out-of-bounds Read, Covert Timing Channel, Detection of Error Condition Without Action, Incorrect Authorization Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2022-23303 The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494. View CVE Details Affected Products Siemens SIDIS Secured SmartPlug Vendor: Siemens Product Version: SIDIS Secured SmartPlug < V7.26.0310 Product Status: known_affected Remediations Vendor fix Update to V7.26.0310 or later version Relevant CWE: CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-23304 The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495. View CV
CSIRTS triage
- What
- Multiple vulnerabilities exist in the SIDIS Secured SmartPlug affecting security and integrity.
- Who is affected
- Deployments of SIDIS Secured SmartPlug before version 7.26.0310.
- Urgency
- Critical remediation is required due to high severity vulnerabilities.
- Action
- Update to the latest version of SIDIS Secured SmartPlug.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch SIDIS Secured SmartPlug
Get an email when a new SIDIS Secured SmartPlug advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-04
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2022-233033.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 86% of all scored CVEs.
- Moderate exploitation riskCVE-2019-94943.9% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 89% of all scored CVEs.
- Moderate exploitation riskCVE-2022-233041.9% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 78% of all scored CVEs.
- Moderate exploitation riskCVE-2019-94953.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 88% of all scored CVEs.
- Low exploitation riskCVE-2022-376600.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all scored CVEs.
- Moderate exploitation riskCVE-2022-481743.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 87% of all scored CVEs.
- Low exploitation riskCVE-2025-52220.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2025-59140.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
- Moderate exploitation riskCVE-2025-92301.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 76% of all scored CVEs.
- Moderate exploitation riskCVE-2025-92312.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 81% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2022-23303 | coverage & exploitation status | NVD · CVE.org |
| CVE-2019-9494 | coverage & exploitation status | NVD · CVE.org |
| CVE-2022-23304 | coverage & exploitation status | NVD · CVE.org |
| CVE-2019-9495 | coverage & exploitation status | NVD · CVE.org |
| CVE-2022-37660 | coverage & exploitation status | NVD · CVE.org |
| CVE-2022-48174 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-5222 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-5914 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-9230 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-9231 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-9232 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-26465 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-32462 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-5121 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] OpenSSL and LibreSSL: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Siebel CRM: Multiple vulnerabilitiescert-bund
- critical[UPDATE] [critical] Apple macOS: Multiple Vulnerabilitiescert-bund
- unknownNCSC-2026-0229 [1.00] [M/H] Vulnerabilities fixed in Siemens productsncsc-nl
- criticalSiemens SINEC OScisa
- medium[UPDATE] [medium] libarchive: Vulnerability allows code executioncert-bund
More from CISA Cybersecurity Advisories
- criticalWatchfire Controller Software2026-07-30
- criticalMZ Automation GmbH libiec618502026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalMikroTik RouterOS2026-07-30