Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-58115PATCHED
Siemens · SIMATIC IoT2050 Advanced

CVE-2026-58115: A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running In

Description

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.

Affected Products

VendorProductVersions
SiemensSIMATIC IoT2050 Advanced0

References

  • https://cert-portal.siemens.com/productcert/html/ssa-834709.html

Related News (2 articles)

Tier B
CERT-FR18h ago
Multiples vulnérabilités dans les produits Siemens (12 août 2026)
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-58115 | Siemens SIMATIC IoT2050 Advanced prior 4.3.4.1 Node-RED HTTP interface improper authentication
→ No new info (linked only)
CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
V4.3.4.1
CWECWE-306
PublishedAug 11, 2026
Last enriched1d ago
Trending Score39
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-59693
CVE-2026-59693: A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.
Trending: 32
HIGHCVE-2026-50063
CVE-2026-50063: A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi
Trending: 29
HIGHCVE-2026-50061
CVE-2026-50061: A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi
Trending: 29
HIGHCVE-2026-50064
CVE-2026-50064: A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi
Trending: 29
HIGHCVE-2026-59701
CVE-2026-59701: A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains a
Trending: 29

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026
Patch Available
Aug 11, 2026