logo

Siemens SIMATIC IoT2050 Advanced

ID: 91cecd80-cda3-55d0-835b-fdd57caca486

STIX ID: report--91cecd80-cda3-55d0-835b-fdd57caca486

Feed Name: CISA Advisories

Threat Score
85/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: CISA

...
...

Siemens and CISA warn of a critical (CVSS v3 10) missing-authentication vulnerability in the Node-RED HTTP interface on SIMATIC IoT2050 Advanced devices (Industrial OS with Node-RED, versions < V4.3.4.1) that allows unauthenticated remote attackers to create malicious flows and achieve arbitrary code execution with maximum privileges; Siemens has released an updated firmware and recommends immediate patching and network protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.