CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Siemens SIMATIC IoT2050 Advanced

criticalCVE-2026-58115
View CSAF Summary SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version. The following versions of Siemens SIMATIC IoT2050 Advanced are affected: SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) vers:intdot/<4.3.4.1 CVSS Vendor Equipment Vulnerabilities v3 10 Siemens Siemens SIMATIC IoT2050 Advanced Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-58115 Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges. View CVE Details Affected Products Siemens SIMATIC IoT2050 Advanced Vendor: Siemens Product Version: SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) < V4.3.4.1 running Industrial OS with Node-RED installed Product Status: known_affected Remediations Mitigation Harden the Node-RED installation (see Node-RED User Guide) Mitigation Uninstall Node-RED Vendor fix Update to V4.3.4.1 or later version https://support.industry.siemens.com/cs/ww/en/view/109741799/ Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Acknowledgments Siemens

CSIRTS triage

What
SIMATIC IoT2050 Advanced with Node-RED lacks authentication on the HTTP interface, allowing unauthenticated attackers to create malicious flows and execute arbitrary code with maximum privileges.
Who is affected
Siemens SIMATIC IoT2050 Advanced devices (6ES7647-0BA00-1YA2) running Industrial OS with Node-RED installed, deployed worldwide in critical infrastructure.
Urgency
Critical; unauthenticated remote code execution with maximum privileges allows complete device and infrastructure compromise.
Action
Update SIMATIC IoT2050 Advanced to version 4.3.4.1 or later immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Siemens SIMATIC IoT2050 Advanced

Get an email when a new Siemens SIMATIC IoT2050 Advanced advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-08-25
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-58115coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Cybersecurity Advisories