PatchSiren cyber security CVE debrief
CVE-2026-58115 Siemens CVE debrief
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.
- Vendor
- Siemens
- Product
- SIMATIC IoT2050 Advanced
- CVSS
- CRITICAL 10
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-08-28
Who should care
Organizations using SIMATIC IoT2050 Advanced devices with Node-RED installed, Industrial Control Systems administrators, and cybersecurity teams responsible for ICS security should prioritize patching and compensating controls due to the critical CVSS score of 10 and potential for unauthenticated remote code execution. These teams should verify affected scope, implement authentication and authorization for Node-RED, and monitor for suspicious activity.
Technical summary
The vulnerability allows unauthenticated remote attackers to execute arbitrary code on the underlying server with maximum privileges by creating malicious flows through the Node-RED HTTP interface. Affected devices are SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) with Node-RED installed, running Industrial OS versions before V4.3.4.1. Organizations should verify affected scope, implement authentication and authorization for Node-RED, restrict access to programming nodes, and monitor for suspicious activity to mitigate potential impacts. Evidence from official CVE Program record and NIST NVD detail page confirms the vulnerability in SIMATIC IoT2050 Advanced devices, but limited information is available on affected scope and vendor remediation efforts.
Defensive priority
High priority due to critical CVSS score of 10 and potential for unauthenticated remote code execution.
Recommended defensive actions
- Inventory and verify SIMATIC IoT2050 Advanced devices for Node-RED installation and version checks
- Implement authentication and authorization for Node-RED HTTP interface
- Restrict access to programming nodes and monitor for suspicious activity
- Apply vendor-provided patches or updates when available
- Consider compensating controls such as network segmentation and intrusion detection
Evidence notes
Evidence from official CVE Program record and NIST NVD detail page confirms the vulnerability in SIMATIC IoT2050 Advanced devices. Limited information available on affected scope and vendor remediation efforts. Defenders should verify Node-RED installation, check for authentication enforcement, and monitor for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-58115 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-58115
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-58115 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58115
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-834709.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.