Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-58115: SIMATIC IoT2050 Advanced: Unauthenticated Access to System Commands
CVE-2026-58115 · published 24 days ago
Summary
Certain versions of SIMATIC IoT2050 Advanced without the latest security patch allow unauthenticated remote access to programming nodes that can execute system commands. This could let an attacker run malicious code on the server with full access. Update to version V4.3.4.1 or later to fix this issue.
What to do
- Update siemens simatic iot2050 advanced to version V4.3.4.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| siemens | simatic iot2050 advanced | < V4.3.4.1 |
Original advisory text
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authent...
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server.
This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.
This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.
Severity
10.0
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published11 Aug 2026
Updated3 Sep 2026
First seen11 Aug 2026
Monitor software like this
Free during beta