Siemens SIMATIC IoT2050 Advanced

Plan PatchCVSS 10ICS-CERT ICSA-26-237-03Aug 11, 2026
SiemensManufacturing
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED contain a missing authentication vulnerability in the Node-RED HTTP interface. An unauthenticated remote attacker can create malicious flows and execute arbitrary code on the underlying server with maximum privileges (CVSS 10.0). This affects all versions below 4.3.4.1.

What this means
What could happen
An unauthenticated attacker could connect to the Node-RED interface on an IoT2050 Advanced device and execute arbitrary code with full system privileges, potentially shutting down operations, altering production settings, or corrupting data.
Who's at risk
Manufacturing facilities using Siemens SIMATIC IoT2050 Advanced edge controllers with Industrial OS and Node-RED installed. This affects any organization using these devices for production monitoring, data collection, or process automation.
How it could be exploited
An attacker on the network (or internet if the device is exposed) sends HTTP requests to the Node-RED HTTP interface port without any credentials. They create malicious flows and deploy them, which execute arbitrary commands on the underlying server with root/system privileges.
Prerequisites
  • Network access to the Node-RED HTTP interface port (default port 1880)
  • Node-RED installed on the SIMATIC IoT2050 Advanced
  • No authentication required
remotely exploitableno authentication requiredlow complexityaffects safety systems (if used in process control)network-accessible edge device
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (1)
ProductAffected VersionsFix Status
SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) < V4.3.4.1 running Industrial OS with Node-RED installed< 4.3.4.14.3.4.1
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to the Node-RED HTTP interface port using a firewall or network segmentation, allowing only trusted engineering workstations or administrative networks
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate SIMATIC IoT2050 Advanced to firmware version 4.3.4.1 or later
Long-term hardening
0/1
HARDENINGIf Node-RED is not required for operations, uninstall it from the SIMATIC IoT2050 Advanced device
API: /api/v1/advisories/3c4db7ed-9d7f-437d-84af-3f44170a9b7d

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Siemens SIMATIC IoT2050 Advanced | CVSS 10 - OTPulse