Back to Feed
VulnerabilitiesJul 21, 2026

Siemens SIDIS Secured SmartPlug

Siemens SIDIS Secured SmartPlug V7.26.0310 and earlier affected by multiple vulnerabilities.

Summary

Siemens SIDIS Secured SmartPlug devices with versions prior to V7.26.0310 are impacted by numerous vulnerabilities, including issues in OpenSSL and OpenSSH. These flaws range from improper message integrity enforcement and key reuse to buffer overflows and timing side-channels, with some rated as critical. Siemens has released an updated version, V7.26.0310, and strongly recommends users update to the latest release.

Full text

ICS Advisory Siemens SIDIS Secured SmartPlug Release DateJuly 21, 2026 Alert CodeICSA-26-202-04 Related topics: Industrial Control System Vulnerabilities , Industrial Control Systems View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version. The following versions of Siemens SIDIS Secured SmartPlug are affected: SIDIS Secured SmartPlug vers:intdot/<7.26.0310 CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens SIDIS Secured SmartPlug Improper Enforcement of Message Integrity During Transmission in a Communication Channel, Reusing a Nonce, Key Pair in Encryption, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Out-of-bounds Read, Covert Timing Channel, Detection of Error Condition Without Action, Incorrect Authorization Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2022-23303 The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494. View CVE Details Affected Products Siemens SIDIS Secured SmartPlug Vendor:Siemens Product Version:SIDIS Secured SmartPlug < V7.26.0310 Product Status:known_affected Remediations Vendor fixUpdate to V7.26.0310 or later version Relevant CWE: CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-23304 The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495. View CVE Details Affected Products Siemens SIDIS Secured SmartPlug Vendor:Siemens Product Version:SIDIS Secured SmartPlug < V7.26.0310 Product Status:known_affected Remediations Vendor fixUpdate to V7.26.0310 or later version Relevant CWE: CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel Metrics CVSS Version Base Score Base Severity Vector String 3.1 7 HIGH CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-37660 In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future bootstrapping by passively observing public keys, re-using the encrypting element Qi and subtracting it from the captured message M (X = M - Qi). This will result in the public ephemeral key X; the only element required to subvert the PKEX association. View CVE Details Affected Products Siemens SIDIS Secured SmartPlug Vendor:Siemens Product Version:SIDIS Secured SmartPlug < V7.26.0310 Product Status:known_affected Remediations Vendor fixUpdate to V7.26.0310 or later version Relevant CWE: CWE-323 Reusing a Nonce, Key Pair in Encryption Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVE-2022-48174 There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. View CVE Details Affected Products Siemens SIDIS Secured SmartPlug Vendor:Siemens Product Version:SIDIS Secured SmartPlug < V7.26.0310 Product Status:known_affected Remediations Vendor fixUpdate to V7.26.0310 or later version Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2025-5222 A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution. View CVE Details Affected Products Siemens SIDIS Secured SmartPlug Vendor:Siemens Product Version:SIDIS Secured SmartPlug < V7.26.0310 Product Status:known_affected Remediations Vendor fixUpdate to V7.26.0310 or later version Relevant CWE: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Metrics CVSS Version Base Score Base Severity Vector String 3.1 7 HIGH CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2025-5914 A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition. View CVE Details Affected Products Siemens SIDIS Secured SmartPlug Vendor:Siemens Product Version:SIDIS Secured SmartPlug < V7.26.0310 Product Status:known_affected Remediations Vendor fixUpdate to V7.26.0310 or later version Relevant CWE: CWE-190 Integer Overflow or Wraparound Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2025-9230 Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. View CVE Details Affected Products Siemens SIDIS Secured SmartPlug Vendor:Siemens Product Version:SIDIS Secured SmartPlug < V7.26.0310 Product Status:known_affected Remediations Vendor fixUpdate to V7.26.0310 or later version Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9231 Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel in SM2 signature computations on 64 bit ARM platforms could allow recovering the private key by an attacker.. While remote key recovery over a network was not attempted by the reporter, timing measurements revealed a timing signal which may allow such an attack. OpenSSL does not directly support certificates with SM2 keys in TLS, and so this CVE is not relevant in most TLS contexts. However, given that it is possible to add support for such certificates via a custom provider, coupled with the fact that in such a custom provider context the private key may be recoverable via remote timing measurements, we consider this to be a Moderate severity issue. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as SM2 is not an approved algorithm. View CVE Details Affected Products Siemens SIDIS Sec

Indicators of Compromise

  • cve — CVE-2022-23303
  • cve — CVE-2022-23304
  • cve — CVE-2022-37660
  • cve — CVE-2022-48174
  • cve — CVE-2025-5222
  • cve — CVE-2025-5914
  • cve — CVE-2025-9230
  • cve — CVE-2025-9231
  • cve — CVE-2025-9232
  • cve — CVE-2026-5121
  • cve — CVE-2025-26465
  • cve — CVE-2025-32462

Entities

SIDIS Secured SmartPlug (product)Siemens (vendor)OpenSSL (technology)OpenSSH (technology)BusyBox (technology)libarchive (technology)