CVE-2019-9495
View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version. The following versions of Siemens SIDIS Secured SmartPlug are affected: SIDIS Secured SmartPlug vers:intdot/<7.26.0310 CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens SIDIS Secured SmartPlug Improper Enforcement of Message Integrity During Transmission in a Communication Channel, Reusing a Nonce, Key Pair in Encryption, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Out-of-bounds Read, Covert Timing Channel, Detection of Error Condition Without Action, Incorrect Authorization Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2022-23303 The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494. View CVE Details Affected Products Siemens SIDIS Secured SmartPlug Vendor: Siemens Product Version: SIDIS Secured SmartPlug < V7.26.0310 Product Status: known_affected Remediations Vendor fix Update to V7.26.0310 or later version Relevant CWE: CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-23304 The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495. View CV
CSIRTS triage
- What
- Multiple vulnerabilities exist in the SIDIS Secured SmartPlug affecting security and integrity.
- Who is affected
- Deployments of SIDIS Secured SmartPlug before version 7.26.0310.
- Urgency
- Critical remediation is required due to high severity vulnerabilities.
- Action
- Update to the latest version of SIDIS Secured SmartPlug.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2019-9495
Get an email if CVE-2019-9495 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Moderate exploitation risk3.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 88% of all EPSS-scored CVEs.
Advisory coverage (2)
- criticalSiemens SIDIS Secured SmartPlugcisa · 2026-07-21
- unknownNCSC-2026-0229 [1.00] [M/H] Vulnerabilities fixed in Siemens productsncsc-nl · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2019-9495)