Security & Threat Intelligence · 21.07.2026, 21:21 UTC
Siemens SIDIS Secured SmartPlug
| Schweregrad | info |
|---|---|
| CVE | ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories · CISA ICS Advisories ↗ |
| Veröffentlicht | 21.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2019-9494, CVE-2019-9495, CVE-2022-23303, CVE-2022-23304, CVE-2022-37660. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version. The following versions of Siemens SIDIS Secured SmartPlug are affected:
SIDIS Secured SmartPlug vers:intdot/<7.26.0310
CVSS Vendor Equipment Vulnerabilities
v3 9.8 Siemens Siemens SIDIS Secured SmartPlug Improper Enforcement of Message Integrity During Transmission in a Communication Channel, Reusing a Nonce, Key Pair in Encryption, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Out-of-bounds Read, Covert Timing Channel, Detection of Error Condition Without Action, Incorrect Authorization
Background
Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2022-23303
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494. View CVE Details
Affected Products Siemens SIDIS Secured SmartPlug
Vendor:Siemens Product Version:SIDIS Secured SmartPlug < V7.26.0310 Product Status:known_affected
Remediations Vendor fixUpdate to V7.26.0310 or later version
Relevant CWE: CWE-924 Improper Enforcement of Message Integrity During …