Siemens Industrial Edge Management
Industrial Edge Management contains an authorization bypass vulnerability that allows an unauthenticated remote attacker to impersonate other devices onboarded to the system. This affects Industrial Edge Management Pro (versions before 1.9.5) and Industrial Edge Management Virtual (versions before 2.3.1-1). An attacker could use device impersonation to interact with connected industrial equipment, potentially altering process configurations or commands without legitimate authorization. Siemens has released patched versions that address this issue.
- Network access to the Industrial Edge Management service (port and interface depend on deployment)
- No authentication credentials required to initiate the attack
- One or more legitimate devices must already be onboarded to the management system
Patching may require device reboot — plan for process interruption
/api/v1/advisories/64d23238-944c-4242-9be7-cb1ec43f26a1Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.