criticalOther

Siemens SIDIS Secured SmartPlug Multiple Third-Party Component Vulnerabilities

First seen Jul 22, 2026 · Updated Jul 22, 2026 · CVSS 9.8

ICSOTSiemensSmartPlugcritical-infrastructurethird-party-componentsOpenSSLOpenSSHvulnerability-disclosure

Siemens SIDIS Secured SmartPlug versions before V7.26.0310 are affected by 13 vulnerabilities inherited from bundled third-party components including OpenSSL, OpenSSH, hostapd/wpa_supplicant, busybox, ICU, libarchive, and sudo. The most severe issue (CVE-2022-23303) carries a CVSS v3.1 score of 9.8 and could allow remote attackers to compromise message integrity and confidentiality without authentication. Siemens has released a fixed firmware version and recommends immediate update.

Technical Analysis

The advisory aggregates CVEs across multiple embedded Linux components used in the SmartPlug firmware: CVE-2022-23303/CVE-2022-23304 (side-channel attacks in hostapd/wpa_supplicant SAE and EAP-pwd implementations), CVE-2022-37660 (PKEX key reuse), CVE-2022-48174 (busybox ash.c stack overflow enabling arbitrary code execution), CVE-2025-5222 (ICU genrb stack buffer overflow), CVE-2025-5914 and CVE-2026-5121 (libarchive integer overflow/double-free and heap buffer overflow via crafted ISO9660 images), CVE-2025-9230/9231/9232 (OpenSSL CMS decryption out-of-bounds read/write, SM2 timing side-channel, and HTTP client out-of-bounds read), CVE-2025-26465 (OpenSSH VerifyHostKeyDNS MITM), and CVE-2025-32462 (Sudo host-restriction bypass). Attack vectors range from network-based (AV:N) unauthenticated exploitation for the critical hostapd flaw to local, higher-complexity exploitation requiring crafted files or memory exhaustion for others; combined impact spans confidentiality, integrity, and availability including potential remote code execution. This is an embedded ICS device (industrial smart plug) rather than a host typically running AI agent workloads, so there is no direct plausible impact to AI agent, LLM, or RAG pipeline systems from this advisory.

Affected Systems

Siemens SIDIS Secured SmartPlug, all versions prior to V7.26.0310 (vers:intdot/<7.26.0310)

Indicators of Compromise

  • No specific IOCs published; this is a vulnerability disclosure/advisory rather than an active exploitation campaign. No hashes, IPs, or domains associated.

Remediation Steps

  1. 1

    Update firmware

    Update Siemens SIDIS Secured SmartPlug to version V7.26.0310 or later, which remediates all listed CVEs in bundled third-party components.

  2. 2

    Restrict network exposure

    Ensure SmartPlug devices and other control system assets are not accessible from the internet; place them behind firewalls and segment from business/IT networks.

  3. 3

    Use secure remote access

    If remote access is required, use up-to-date VPN solutions rather than direct exposure, and treat VPN endpoints as part of the attack surface requiring patching.

  4. 4

    Apply defense-in-depth

    Follow Siemens' operational guidelines for Industrial Security and CISA's ICS defense-in-depth recommendations, including network monitoring for anomalous ICS traffic.

  5. 5

    Report suspicious activity

    Organizations observing suspected exploitation attempts should follow internal incident response procedures and report to CISA for tracking and correlation.

CVE / Advisory IDs

CVE-2022-23303CVE-2022-23304CVE-2022-37660CVE-2022-48174CVE-2025-5222CVE-2025-5914CVE-2025-9230CVE-2025-9231CVE-2025-9232CVE-2025-26465CVE-2025-32462CVE-2026-5121

Industries Most Exposed

Critical ManufacturingIndustrial Control SystemsEnergyBuilding Automation

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.