Siemens has an update available to handle a missing authentication for critical function vulnerability in its SIMATIC IoT2050 Advanced, according to a report with CISA.

SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens self-reported the vulnerability.

SIMATIC IoT2050 Advanced is a high-performance, open industrial IoT gateway designed to connect factory floor equipment with enterprise IT and cloud systems.

The following versions of Siemens SIMATIC IoT2050 Advanced suffer from the vulnerability: Versions up to 4.3.4.1.

In the vulnerability, affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.

Schneider Bold

CVE-2026-58115 is the case number for the vulnerability, which has a CVSS V3 base score of 10.

The product sees use in the chemical, critical manufacturing, energy, and transportation systems sectors. It also sees action on a global basis.

In terms of mitigations, users can:

  • Learn how to harden the Node-RED installation in its user guide.
  • Uninstall Node-RED

There is a fix available where users can update to V4.3.4.1 or later version.

As a general security measure, Siemens recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens’ operational guidelines for industrial security.

ISSSource

Pin It on Pinterest

Share This