Siemens SIDIS SmartPlug hit by multiple CVEs
Siemens SIDIS Secured SmartPlug before V7.26.0310 bundles vulnerable OpenSSL, OpenSSH, hostapd, busybox, libarchive and sudo components; Siemens urges upgrading to fix them.
CISA republished a Siemens ProductCERT advisory (SSA-585531) detailing a dozen third-party component vulnerabilities affecting SIDIS Secured SmartPlug versions prior to V7.26.0310, a product used in Critical Manufacturing environments deployed worldwide. The issues stem from outdated bundled open-source components including OpenSSL, OpenSSH, hostapd/wpa_supplicant, busybox, libarchive, and sudo, covering a range of weaknesses from side-channel key recovery and memory corruption to authorization bypass and denial-of-service conditions.
Notable flaws include CVE-2022-48174 (busybox stack overflow enabling arbitrary code execution), CVE-2025-5914 and CVE-2026-5121 (libarchive integer overflow/double-free issues that could lead to code execution via crafted archive or ISO images), and CVE-2025-32462 (a sudo authorization flaw allowing execution on unintended hosts). Several OpenSSL and OpenSSH CVEs (side-channel timing attacks, out-of-bounds reads/writes, and a VerifyHostKeyDNS MITM weakness) round out the set, though most carry high attack complexity or narrow applicability.
No active exploitation has been reported; this is a vendor-driven patch advisory. Siemens recommends updating to V7.26.0310 or later and following standard industrial network segmentation and hardening guidance (isolating control system networks, avoiding direct internet exposure, and using VPNs for remote access) as compensating controls where immediate patching is not feasible.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-04
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free