CISA

Siemens SIMATIC IoT2050 Advanced

From Cybersecurity and Infrastructure Security Agency ↗

SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version.

The following versions of Siemens SIMATIC IoT2050 Advanced are affected:

SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) vers:intdot/