CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2022-23303

criticalcovered by 2 sourcesfirst seen 2026-07-14
View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version. The following versions of Siemens SIDIS Secured SmartPlug are affected: SIDIS Secured SmartPlug vers:intdot/<7.26.0310 CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens SIDIS Secured SmartPlug Improper Enforcement of Message Integrity During Transmission in a Communication Channel, Reusing a Nonce, Key Pair in Encryption, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Out-of-bounds Read, Covert Timing Channel, Detection of Error Condition Without Action, Incorrect Authorization Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2022-23303 The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494. View CVE Details Affected Products Siemens SIDIS Secured SmartPlug Vendor: Siemens Product Version: SIDIS Secured SmartPlug < V7.26.0310 Product Status: known_affected Remediations Vendor fix Update to V7.26.0310 or later version Relevant CWE: CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-23304 The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495. View CV

CSIRTS triage

vendor: Siemensproduct: SIDIS Secured SmartPlugOtheraffected: vers:intdot/<7.26.0310
What
Multiple vulnerabilities exist in the SIDIS Secured SmartPlug affecting security and integrity.
Who is affected
Deployments of SIDIS Secured SmartPlug before version 7.26.0310.
Urgency
Critical remediation is required due to high severity vulnerabilities.
Action
Update to the latest version of SIDIS Secured SmartPlug.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2022-23303

Get an email if CVE-2022-23303 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2022-23303

CVE.org record

Embed the live status

CVE-2022-23303 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2022-23303 status](https://www.csirts.com/badge/CVE-2022-23303)](https://www.csirts.com/cve/CVE-2022-23303)