Siemens SIDIS Secured SmartPlug Multiple Third-Party Component Vulnerabilities
First seen Jul 22, 2026 · Updated Jul 22, 2026 · CVSS 9.8
Siemens SIDIS Secured SmartPlug versions before V7.26.0310 are affected by 13 vulnerabilities inherited from bundled third-party components including OpenSSL, OpenSSH, hostapd/wpa_supplicant, busybox, ICU, libarchive, and sudo. The most severe issue (CVE-2022-23303) carries a CVSS v3.1 score of 9.8 and could allow remote attackers to compromise message integrity and confidentiality without authentication. Siemens has released a fixed firmware version and recommends immediate update.
Technical Analysis
The advisory aggregates CVEs across multiple embedded Linux components used in the SmartPlug firmware: CVE-2022-23303/CVE-2022-23304 (side-channel attacks in hostapd/wpa_supplicant SAE and EAP-pwd implementations), CVE-2022-37660 (PKEX key reuse), CVE-2022-48174 (busybox ash.c stack overflow enabling arbitrary code execution), CVE-2025-5222 (ICU genrb stack buffer overflow), CVE-2025-5914 and CVE-2026-5121 (libarchive integer overflow/double-free and heap buffer overflow via crafted ISO9660 images), CVE-2025-9230/9231/9232 (OpenSSL CMS decryption out-of-bounds read/write, SM2 timing side-channel, and HTTP client out-of-bounds read), CVE-2025-26465 (OpenSSH VerifyHostKeyDNS MITM), and CVE-2025-32462 (Sudo host-restriction bypass). Attack vectors range from network-based (AV:N) unauthenticated exploitation for the critical hostapd flaw to local, higher-complexity exploitation requiring crafted files or memory exhaustion for others; combined impact spans confidentiality, integrity, and availability including potential remote code execution. This is an embedded ICS device (industrial smart plug) rather than a host typically running AI agent workloads, so there is no direct plausible impact to AI agent, LLM, or RAG pipeline systems from this advisory.
Affected Systems
Siemens SIDIS Secured SmartPlug, all versions prior to V7.26.0310 (vers:intdot/<7.26.0310)
Indicators of Compromise
- No specific IOCs published; this is a vulnerability disclosure/advisory rather than an active exploitation campaign. No hashes, IPs, or domains associated.
Remediation Steps
- 1
Update firmware
Update Siemens SIDIS Secured SmartPlug to version V7.26.0310 or later, which remediates all listed CVEs in bundled third-party components.
- 2
Restrict network exposure
Ensure SmartPlug devices and other control system assets are not accessible from the internet; place them behind firewalls and segment from business/IT networks.
- 3
Use secure remote access
If remote access is required, use up-to-date VPN solutions rather than direct exposure, and treat VPN endpoints as part of the attack surface requiring patching.
- 4
Apply defense-in-depth
Follow Siemens' operational guidelines for Industrial Security and CISA's ICS defense-in-depth recommendations, including network monitoring for anomalous ICS traffic.
- 5
Report suspicious activity
Organizations observing suspected exploitation attempts should follow internal incident response procedures and report to CISA for tracking and correlation.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.