Siemens SIMATIC IoT2050 Advanced
ID: 91cecd80-cda3-55d0-835b-fdd57caca486
STIX ID: report--91cecd80-cda3-55d0-835b-fdd57caca486
Feed Name: CISA Advisories
Threat Score
Siemens and CISA warn of a critical (CVSS v3 10) missing-authentication vulnerability in the Node-RED HTTP interface on SIMATIC IoT2050 Advanced devices (Industrial OS with Node-RED, versions < V4.3.4.1) that allows unauthenticated remote attackers to create malicious flows and achieve arbitrary code execution with maximum privileges; Siemens has released an updated firmware and recommends immediate patching and network protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
