Cyber Resilience
← All news
Confirmed

Siemens Industrial Edge Management

Our takeSiemens fixed an authentication bypass in Industrial Edge Management that lets unauthenticated remote attackers reset credentials and take over accounts. Update to the latest version immediately if you run it.
Sources (1)
What this means for you — Security leader:Update all Siemens Industrial Edge Management instances to the latest version immediately; the authentication bypass allows unauthenticated remote account takeover via credential reset.
What this means for you — Lean IT orgs:If you use Siemens Industrial Edge Management, update it to the newest version right away — an unauthenticated attacker can take over accounts without email checks.
What this means for you — MSP:Check every client running Siemens Industrial Edge Management and push the newest version; the authentication bypass enables full remote account takeover without email verification.
What this means for you — Researcher:Review the CSAF and CISA advisory for Siemens Industrial Edge Management (ICSA-26-265-06) and test the credential-reset bypass in your environment.