Siemens SIMATIC IoT2050 Advanced
Brief
View CSAF
Summary
SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges.
Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version.
The following versions of Siemens SIMATIC IoT2050 Advanced are affected:
- SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) vers:intdot/
