CVE-2026-58115
Received Received - Intake

Unauthenticated Remote Code Execution in SIMATIC IoT2050

Vulnerability report for CVE-2026-58115, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Siemens AG

Description

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
siemens iot2050 to 4.3.4.1 (exc)
siemens simatciot2050_advanced to 4.3.4.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed. The Node-RED HTTP interface lacks authentication, allowing unauthenticated remote attackers to access programming nodes that can execute system commands on the server with maximum privileges.

Detection Guidance

Check if Node-RED is installed and running on SIMATIC IoT2050 Advanced devices by inspecting network services on port 1880. Verify if the HTTP interface is accessible without authentication by attempting to access the Node-RED editor or API endpoints.

Impact Analysis

An attacker could exploit this to create malicious flows via the HTTP interface and execute arbitrary code on the server with full system privileges. This could lead to complete system compromise, unauthorized data access, or disruption of operations.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating confidentiality requirements in GDPR and HIPAA. Non-compliance may result in legal penalties, fines, or reputational damage due to exposed sensitive data.

Mitigation Strategies

Update affected devices to Industrial OS version V4.3.4.1 or later. As temporary mitigations, uninstall Node-RED or restrict network access to the device. Follow Siemens operational guidelines for Industrial Security.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58115. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart