ics-otregulatorNewsThe Broadside1 min read

CISA flags Siemens SmartPlug flaws rated CVSS 9.8

This is the familiar OT appliance problem: inherited open-source defects become plant-floor exposure on someone else’s patch calendar.


TL;DR

CISA warned that Siemens SIDIS Secured SmartPlug versions before V7.26.0310 carry multiple vulnerabilities in OpenSSL, OpenSSH, hostapd, busybox and other packages, including a CVSS 9.8 issue. Siemens released V7.26.0310 and recommends updating. Contractors, MSPs and ISVs supporting critical manufacturing deployments should treat this as an OT maintenance item, not a paperwork entry.

CISA’s advisory is routine in form and ugly in content: SIDIS Secured SmartPlug versions before V7.26.0310 inherit a stack of component vulnerabilities across OpenSSL, OpenSSH, hostapd, busybox and other packages, with the top rating at CVSS 9.8. Siemens has issued the fixed version and the operational answer is simple to state: update affected SmartPlug devices to V7.26.0310 or later.

The harder part is the usual OT reality. A SmartPlug sitting in a critical manufacturing environment is not patched like a laptop, and CISA does not resolve the deployment problem for air-gapped or change-controlled networks. Contractors, MSPs and ISVs with responsibility for these environments need the asset inventory, the firmware version check and the maintenance window. The advisory does not specify whether exploits are public or active, which is useful to know but not a reason to wait.


Published ·Deep Fathom