Critical Flaw in Siemens SIMATIC IoT2050 Advanced Devices Allows Full Remote Takeover
Siemens has disclosed a critical security flaw affecting its SIMATIC IoT2050 Advanced industrial devices when running Industrial OS with Node-RED installed. The vulnerability, rated 10 out of 10 on the CVSS severity scale, stems from missing authentication in the Node-RED HTTP interface. This means an attacker could remotely create malicious automation 'flows' and execute arbitrary code on the device with the highest level of system privileges, without needing any login credentials.
The affected product is SIMATIC IoT2050 Advanced (model 6ES7647-0BA00-1YA2) running versions earlier than 4.3.4.1. These devices are used worldwide across critical infrastructure sectors including chemical, critical manufacturing, energy, and transportation systems, making the potential impact significant if exploited.
Siemens has released an updated software version to fix this issue and strongly urges all affected users to update immediately. Given the maximum severity rating and the lack of authentication required to exploit it, this vulnerability should be treated as an urgent priority for any organisation using these devices.