Skip to content
SiemensCVE-2026-58115

Siemens SIMATIC IoT2050 Advanced: remote code execution

Critical10.0CVE-2026-58115 · Published Aug 11, 2026 · updated Aug 28, 2026

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.

Siemens advisory

Affected versions

PackageAffectedFixed in
SIMATIC IoT2050 Advanced
Product
< V4.3.4.1V4.3.4.1
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-306

More Siemens advisories

All Siemens
Advisory
Siemens License Server (SLS): path traversal
High8.7Aug 11
Siemens Parasolid: out-of-bounds read
High7.3Aug 11
Siemens License Server (SLS): privilege escalation
High8.3Aug 11
Siemens Simcenter: code execution
High7.3Aug 11
Siemens Desigo: denial of service
Medium5.3Aug 11
Siemens Simcenter Femap: out-of-bounds read
High7.3Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.