Cyber Resilience
← All news
Confirmed

Siemens SIMATIC IoT2050 Advanced

Our takeSiemens patched a missing-authentication flaw in the Node-RED HTTP interface on SIMATIC IoT2050 Advanced: an unauthenticated remote attacker could create malicious flows and run arbitrary code with maximum privileges. If you run these devices with Node-RED installed, update now.
Sources (1)
What this means for you — Security leader:Siemens released a new firmware version for SIMATIC IoT2050 Advanced that fixes a missing authentication flaw in the Node-RED HTTP interface; unauthenticated remote attackers could create flows and run arbitrary code as root. Update immediately if you deploy these devices in your OT environment.
What this means for you — Lean IT orgs:If you run a Siemens SIMATIC IoT2050 Advanced with Node-RED, install the updated Industrial OS version right away. Most lean teams without these specific devices can ignore this advisory.
What this means for you — MSP:Check every client running Siemens SIMATIC IoT2050 Advanced with Node-RED installed; the new Industrial OS version fixes a missing-authentication flaw that lets remote unauthenticated attackers execute arbitrary code as root. Patch those devices now.
What this means for you — Researcher:Siemens fixed a missing authentication vulnerability (ICSA-26-237-03) in the Node-RED HTTP interface on SIMATIC IoT2050 Advanced running Industrial OS; remote unauthenticated attackers could create malicious flows and gain root execution.