Vulnerabilities · InfosecFeed Brief

Siemens SIMATIC IoT2050 Advanced

Vulnerabilities

What you need to know

SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC…

Source transparency

This is an InfosecFeed curated brief based on reporting from CISA Alerts. InfosecFeed does not claim ownership of the original reporting.

Read the original report at CISA Alerts ↗