← All Advisories

CVE-2026-33892

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-33892

Key Details

CVECVE-2026-33892
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-06-17
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is changed; confidentiality impact is low; integrity impact is low; availability impact is low.
Affected productsSiemens Industrial Edge Management Pro V1, Siemens Industrial Edge Management Pro V2, and Siemens Industrial Edge Management Virtual
Classified asCWE-305 (Authentication Bypass by Primary Weakness)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensIndustrial Edge Management Pro V1
SiemensIndustrial Edge Management Pro V2
SiemensIndustrial Edge Management Virtual
SubsystemsGeneral OT
SectorsMultiple

What to Know

A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Pro V2 (All versions >= V2.0.0 < V2.1.1), Industrial Edge Management Virtual (All versions >= V2.2.0 < V2.8.0). Affected management systems do not properly enforce user authentication on remote connections to devices.

This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user.

Successful exploitation requires that the attacker has identified the header and port used for remote connections to devices and that the remote connection feature is enabled for the device.

Exploitation allows the attacker to tunnel to the device. Security features on this device itself (e.g. app specific authentication) are not affected. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-33892
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-33892