Executive brief
SIMATIC IoT2050 Advanced is an industrial IoT gateway device used to connect operational technology systems to IT networks. The Node-RED programming interface on affected devices lacks authentication controls, allowing anyone on the network to create and execute arbitrary code on the device with administrative privileges. An attacker could remotely compromise the device and gain complete control of connected industrial systems without any credentials.
Technical details
The vulnerability is a missing authentication flaw (CWE-306) in the Node-RED HTTP interface running on SIMATIC IoT2050 Advanced devices. The Node-RED interface allows creation of executable flows without requiring authentication; an attacker can remotely access the interface over the network and use built-in system command nodes to achieve arbitrary code execution with maximum privileges on the underlying Industrial OS. The vulnerability affects all versions of SIMATIC IoT2050 Advanced (model 6ES7647-0BA00-1YA2) prior to V4.3.4.1 when Node-RED is installed. Exploitation requires only network access to the Node-RED HTTP port; no user interaction or prior authentication is required. Siemens has released patched version V4.3.4.1 or later, and recommends either updating immediately or uninstalling Node-RED as interim mitigation.
Affected products
- Siemens SIMATIC IoT2050 Advanced All versions < V4.3.4.1 running Industrial OS with Node-RED installed
Timeline
- 2026-08-11: disclosed: Siemens SSA-834709 published