THREATOPS
THREAT OPSThreat News › Siemens SIMATIC IoT2050 Advanced

Siemens SIMATIC IoT2050 Advanced

medcisa_icsPublished 2026-08-25

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03

Same event, other sources