Impact
SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED before V4.3.4.1 allow an unauthenticated attacker to access the Node-RED HTTP interface, where certain programming nodes can execute system commands on the server. The vulnerability permits creation of malicious flows via HTTP, leading to arbitrary code execution with full system privileges. This represents a severe compromise of the device’s confidentiality, integrity and availability.
Affected Systems
Siemens SIMATIC IoT2050 Advanced (model 6ES7647-0BA00-1YA2) running any version of Industrial OS that has Node-RED installed and is below V4.3.4.1. No other products or versions are listed as affected.
Risk and Exploitability
The CVSS score of 10 underscores that exploitation grants maximum privileges with no authentication required. The lack of an existing KEV listing does not diminish the risk; the vulnerability's nature and high severity make it an attractive target for remote attackers. An attacker can reach the device over the network, send HTTP requests to the unprotected Node-RED interface, and trigger arbitrary code execution without prior compromise.
OpenCVE Enrichment