1. Executive summary
Siemens disclosed CVE-2026-58115 affecting SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) before V4.3.4.1 when running Industrial OS with Node-RED installed. Missing authentication on the Node-RED HTTP interface allows a reachable, unauthenticated attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens and CISA report a CVSS v3.1 score of 10, CRITICAL; no authoritative CISA KEV exploitation state was resolved, and the source provides no evidence of observed exploitation. EMEA financial-services organisations are exposed only where this specific product and configuration are deployed, but successful exploitation could compromise the confidentiality, integrity and availability of the underlying server. Technical claims originate from Siemens ProductCERT SSA-834709, republished verbatim by CISA, and are therefore single-sourced.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The supplied facts describe a product vulnerability, not an incident or item-specific regulatory trigger; they likewise establish no specific trigger under UK NIS 2018.
3. Technical analysis & attack chain
The following is the confirmed vulnerability path, not evidence that exploitation has occurred:
- Required target configuration: The target is a SIMATIC IoT2050 Advanced, product number
6ES7647-0BA00-1YA2, running Industrial OS with Node-RED installed and a version earlier than V4.3.4.1. - Network access: An unauthenticated remote attacker obtains network reachability to the Node-RED HTTP interface. The advisory does not identify a port, URL path or required request format.
- Missing authentication: The affected device does not enforce authentication before permitting access to Node-RED programming nodes. The flaw is classified as CWE-306: Missing Authentication for Critical Function.
- Malicious flow creation: The attacker uses the exposed programming functionality to create a malicious Node-RED flow. No exploit payload, node type, HTTP request or proof-of-concept is provided.
- Command execution: Programming nodes can execute system commands on the underlying server. A malicious flow can therefore produce arbitrary code execution with maximum privileges.
- Potential impact: The reported vector is
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, with a CVSS v3.1 score of 10, CRITICAL. This describes remote, low-complexity exploitation without credentials or user interaction, with high confidentiality, integrity and availability impact.
No authoritative CISA KEV exploitation state was resolved for CVE-2026-58115; it must not be represented as either known-exploited or confirmed not exploited. The sources provide no observed payload, persistence mechanism, privilege-escalation step, command-and-control infrastructure, lateral movement, exfiltration method or incident impact. No threat actor or campaign attribution is reported.
CISA states that its advisory is a verbatim republication of Siemens ProductCERT SSA-834709. This is one underlying source rather than independent corroboration; validate the affected configuration and exposure locally before enforcement.
4. Mitigation & containment
P1 — within 24 hours
- Identify all
6ES7647-0BA00-1YA2devices and establish the installed Industrial OS version and whether Node-RED is installed. Treat versions earlier than V4.3.4.1 as affected. - Update affected devices to V4.3.4.1 or later, following an operational impact and risk assessment before deployment.
- Until updated, block untrusted access to the Node-RED HTTP interface. Remove internet exposure, place affected devices behind firewalls and isolate control-system networks from business networks.
- If Node-RED is unnecessary, uninstall it. If it must remain, harden the installation in accordance with the Node-RED User Guide referenced by Siemens.
- Where remote access is required, restrict it through an up-to-date VPN and approved management path. Do not expose the Node-RED interface directly.
P2 — within 72 hours
- Confirm that unauthenticated sessions can no longer access Node-RED programming functionality after remediation.
- Review configured flows and programming nodes against an approved baseline. Investigate unexplained flow creation or modification and any associated system-command execution.
- Review available Node-RED HTTP, network and host telemetry for access to programming functions followed by flow changes or command execution.
- If an unauthorised flow or command execution is identified, isolate the device and treat the underlying server as compromised with maximum privileges. Preserve relevant configuration and logs, rebuild from a trusted state where required, and rotate credentials accessible from the device.
P3 — within 7 days
- Verify version and configuration compliance across the complete IoT2050 inventory, including devices administered by operational teams or service providers.
- Test network controls to confirm that only authorised management systems can reach the Node-RED interface.
- Record any remediation exception with an owner, compensating network controls and an expiry date.
- Incorporate the affected model, Node-RED presence and minimum fixed version into vulnerability-management and configuration-assurance checks.
5. Indicators of compromise
No indicators of compromise available in the source material.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Access to Node-RED programming functionality without authentication | Node-RED HTTP logs or upstream network telemetry | Medium |
| Unauthorised creation or modification of Node-RED flows | Node-RED configuration and administrative records | Medium |
| System-command execution following Node-RED HTTP activity or flow modification | Host audit/process telemetry correlated with HTTP activity | Medium |
These behaviours derive from the vendor-described exploit mechanism, not an observed intrusion. They are single-sourced; verify before enforcement.
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- CISA, “Siemens SIMATIC IoT2050 Advanced,” 25 August 2026: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03
- Siemens ProductCERT, “SSA-834709” remediation referenced by CISA, 11 August 2026: https://support.industry.siemens.com/cs/ww/en/view/109741799/
8. Adverse Trace position
CVE-2026-58115 carries the Siemens/CISA-reported CVSS v3.1 score of 10, CRITICAL; no authoritative CISA KEV exploitation state was resolved, and no exploitation or actor attribution is confirmed. Client impact is potentially severe where an affected device exposes its Node-RED HTTP interface because exploitation requires neither credentials nor user interaction and yields maximum privileges, but organisations without the specified product and configuration are not affected. Adverse Trace recommends immediate scoping, exposure removal and upgrade to V4.3.4.1 or later. The technical account is single-sourced through Siemens and its verbatim CISA republication; verify before enforcement. Adverse Trace will monitor Siemens and CISA for exploitation evidence, KEV status changes and revised remediation guidance.
Published via PulseTrace — Adverse Trace threat intelligence.