Our takeSiemens released a new version for SIMATIC IoT2050 Advanced to fix a missing authentication vulnerability in the Node-RED HTTP interface. An unauthenticated remote attacker could create malicious flows and execute arbitrary code with maximum privileges. Update now if you run these.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:Update SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED to the latest version. The unauthenticated remote attacker can create malicious flows and execute arbitrary code with maximum privileges.
What this means for you — Lean IT orgs:If you run Siemens SIMATIC IoT2050 Advanced devices with Node-RED installed, update the Industrial OS to the newest version immediately. Most teams without these specific devices can ignore this.
What this means for you — MSP:Check client environments for SIMATIC IoT2050 Advanced running Industrial OS with Node-RED and push the Siemens update. The missing authentication flaw allows unauthenticated remote code execution at maximum privileges.
What this means for you — Researcher:Review the new Siemens firmware and Node-RED configuration hardening options published in the advisory.