Authentication Bypass Vulnerability in Industrial Edge Management
Plan PatchCVSS 9.1SSA-503852Sep 8, 2026
SiemensManufacturing
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Industrial Edge Management contains an authentication bypass vulnerability that allows an unauthenticated remote attacker to reset any user's password without email verification, enabling full account takeover. The vulnerability exists in the password reset endpoint and affects Industrial Edge Management Cloud (all versions), Pro V1 (versions 1.14.9 to 1.15.19), Pro V2 (versions 2.2.0 to 2.2.1), and Virtual (versions 2.6.0 to 2.9.0). Siemens has released patches for all affected product lines.
What this means
What could happen
An attacker without credentials can reset any user's password and gain full account access to your Industrial Edge Management system, potentially allowing them to modify device configurations, access sensitive data, or disrupt manufacturing operations.
Who's at risk
Manufacturing facilities running Siemens Industrial Edge Management (Pro or Virtual versions) for edge computing and device management. This affects any organization that exposes IEM to the internet or untrusted networks for remote administration or cloud connectivity.
How it could be exploited
An attacker sends a credential reset request to the affected endpoint (/auth/realms/customer/login-actions/reset-credentials) without authentication. The system bypasses email verification and generates a password reset token that can be used to change the target user's credentials, granting full account access to the platform.
Prerequisites
- Network access to the Industrial Edge Management system on the internet or reachable network
- No authentication credentials required
- Password reset feature enabled in Keycloak realm settings
remotely exploitableno authentication requiredlow complexityhigh CVSS score (9.1)
Exploitability
Some exploitation risk — EPSS score 3.2%
Public Proof-of-Concept (PoC) on GitHub (10 repositories)
Affected products (4)
4 with fix
ProductAffected VersionsFix Status
Industrial Edge Management CloudAll versionsFix available
Remediation & Mitigation
0/4
Do now
0/3WORKAROUNDBlock direct internet access to your Industrial Edge Management Pro or Virtual instance at the firewall or network boundary
WORKAROUNDConfigure a Web Application Firewall (WAF) or Reverse Proxy to block the path /auth/realms/customer/login-actions/reset-credentials
HARDENINGDisable password reset functionality in Keycloak realm settings: Identity & access management > realm settings > Login > Forgot password > Off
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate Industrial Edge Management Pro to version 1.15.20 or later, and Industrial Edge Management Virtual to version 2.9.1 or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/e5d70562-9952-42ef-b22c-e3b45f0c5a97Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.