Description
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server.
This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.
Published: 2026-08-11
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED before V4.3.4.1 allow an unauthenticated attacker to access the Node-RED HTTP interface, where certain programming nodes can execute system commands on the server. The vulnerability permits creation of malicious flows via HTTP, leading to arbitrary code execution with full system privileges. This represents a severe compromise of the device’s confidentiality, integrity and availability.

Affected Systems

Siemens SIMATIC IoT2050 Advanced (model 6ES7647-0BA00-1YA2) running any version of Industrial OS that has Node-RED installed and is below V4.3.4.1. No other products or versions are listed as affected.

Risk and Exploitability

The CVSS score of 10 underscores that exploitation grants maximum privileges with no authentication required. The lack of an existing KEV listing does not diminish the risk; the vulnerability's nature and high severity make it an attractive target for remote attackers. An attacker can reach the device over the network, send HTTP requests to the unprotected Node-RED interface, and trigger arbitrary code execution without prior compromise.

Generated by OpenCVE AI on August 11, 2026 at 23:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to V4.3.4.1 or later to secure the Node-RED HTTP interface
  • Disabling or restricting access to the Node-RED HTTP port within the device’s network firewall
  • Implement network segmentation to isolate the IoT2050 unit and monitor for anomalous activity

Generated by OpenCVE AI on August 11, 2026 at 23:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Node‑RED Interface Enables Remote Code Execution on Siemens SIMATIC IoT2050 Advanced

Tue, 11 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-08-11T12:20:24.045Z

Reserved: 2026-06-29T12:59:54.795Z

Link: CVE-2026-58115

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-11T13:19:00.190

Modified: 2026-08-11T13:19:00.190

Link: CVE-2026-58115

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T00:00:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function