Our takeSiemens fixed an authentication bypass in Industrial Edge Management (ICSA-26-265-06) that lets unauthenticated remote attackers reset credentials and take over accounts. Update to the latest version if you run it.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:Update Siemens Industrial Edge Management to the latest version; the authentication bypass lets unauthenticated attackers reset credentials and take over accounts without email verification.
What this means for you — Lean IT orgs:If you run Siemens Industrial Edge Management, update it to the newest version right away — it has a flaw that lets outsiders take over accounts without any login.
What this means for you — MSP:Check client environments for Siemens Industrial Edge Management and push the vendor's latest versions; the authentication bypass allows full account takeover by resetting credentials without email verification.
What this means for you — Researcher:Siemens fixed an authentication bypass in Industrial Edge Management that permits unauthenticated remote account takeover via credential reset without email verification.