Siemens SIDIS Secured SmartPlug
Plan PatchCVSS 9.8ICS-CERT ICSA-26-202-04Jul 14, 2026
Siemens
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
SIDIS Secured SmartPlug before V7.26.0310 contains multiple critical vulnerabilities in OpenSSL, OpenSSH, and other components that allow remote attackers to execute arbitrary code, bypass authentication, or cause denial of service. The vulnerabilities include buffer overflows, cryptographic weaknesses, and integer overflows with CVSS 9.8 and no authentication required.
What this means
What could happen
An attacker who gains network access to SIDIS Secured SmartPlug could remotely execute commands, modify firmware, or disrupt device operations due to multiple critical vulnerabilities in OpenSSL, OpenSSH, and other components. This could lead to unauthorized control of connected equipment or service interruption.
Who's at risk
Water authorities and electric utilities using SIDIS Secured SmartPlug for remote device management and encrypted communications are affected. Any facility with SmartPlug devices versions prior to V7.26.0310 should prioritize this update.
How it could be exploited
An attacker on the network can connect to the SmartPlug without authentication and exploit buffer overflow, cryptographic, or authentication bypass vulnerabilities in OpenSSL or OpenSSH to execute arbitrary code or gain administrative access to the device.
Prerequisites
- Network connectivity to SIDIS Secured SmartPlug
- Device running firmware version prior to V7.26.0310
- No valid authentication required
remotely exploitableno authentication requiredlow complexityhigh CVSS score (9.8)critical severitymultiple vulnerabilities in widely-used crypto libraries
Exploitability
Some exploitation risk — EPSS score 7.7%
Public Proof-of-Concept (PoC) on GitHub (10 repositories)
Affected products (1)
ProductAffected VersionsFix Status
SIDIS Secured SmartPlug < V7.26.0310< 7.26.03107.26.0310
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate SIDIS Secured SmartPlug to firmware version V7.26.0310 or later
CVEs (12)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/9dd31084-0603-4279-bbba-5ec7c6f2075fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.