PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-58115 Siemens CVE debrief

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.

Vendor
Siemens
Product
SIMATIC IoT2050 Advanced
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-08-28
Advisory published
2026-08-11
Advisory updated
2026-08-28

Who should care

Organizations using SIMATIC IoT2050 Advanced devices with Node-RED installed, Industrial Control Systems administrators, and cybersecurity teams responsible for ICS security should prioritize patching and compensating controls due to the critical CVSS score of 10 and potential for unauthenticated remote code execution. These teams should verify affected scope, implement authentication and authorization for Node-RED, and monitor for suspicious activity.

Technical summary

The vulnerability allows unauthenticated remote attackers to execute arbitrary code on the underlying server with maximum privileges by creating malicious flows through the Node-RED HTTP interface. Affected devices are SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) with Node-RED installed, running Industrial OS versions before V4.3.4.1. Organizations should verify affected scope, implement authentication and authorization for Node-RED, restrict access to programming nodes, and monitor for suspicious activity to mitigate potential impacts. Evidence from official CVE Program record and NIST NVD detail page confirms the vulnerability in SIMATIC IoT2050 Advanced devices, but limited information is available on affected scope and vendor remediation efforts.

Defensive priority

High priority due to critical CVSS score of 10 and potential for unauthenticated remote code execution.

Recommended defensive actions

  • Inventory and verify SIMATIC IoT2050 Advanced devices for Node-RED installation and version checks
  • Implement authentication and authorization for Node-RED HTTP interface
  • Restrict access to programming nodes and monitor for suspicious activity
  • Apply vendor-provided patches or updates when available
  • Consider compensating controls such as network segmentation and intrusion detection

Evidence notes

Evidence from official CVE Program record and NIST NVD detail page confirms the vulnerability in SIMATIC IoT2050 Advanced devices. Limited information available on affected scope and vendor remediation efforts. Defenders should verify Node-RED installation, check for authentication enforcement, and monitor for suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-58115 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-58115

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-58115 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58115

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.