CVE-2019-9494
CVSS 5.9 MEDIUM: the implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. EPSS 4% (89º percentile).
Vulnerabilità ed exploit
Il punto non è solo che lo SmartPlug ha più CVE. Il punto è che un dispositivo che sembra semplice hardware di alimentazione eredita difetti nel suo stack wireless e di autenticazione, e può così indebolire bootstrap delle chiavi e controllo degli accessi nell’ambiente OT.
CISA e Siemens indicano che SIDIS Secured SmartPlug prima di V7.26.0310 è affetto da vulnerabilità in OpenSSL, OpenSSH e altri pacchetti integrati. Tra le ancore citate figurano CVE-2022-23303 e CVE-2019-9494; Siemens ha rilasciato V7.26.0310 e raccomanda l’aggiornamento alla versione corretta.
Per chi gestisce questi apparati in manufacturing, la verifica dello stato di patching conta più del singolo numero di CVE: il rischio è fidarsi di un dispositivo che conserva componenti vulnerabili già noti, non di un bug isolato nel firmware del prodotto.
1 fonte · 21 lug
CVSS 5.9 MEDIUM: the implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. EPSS 4% (89º percentile).
CVSS 9.8 CRITICAL: the implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. EPSS 3% (86º percentile).
CISA Advisories
Siemens SIDIS Secured SmartPlug | CISA
Siemens SIDIS Secured SmartPlug Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below.
originalePart of the PlainSec briefing for 2026-07-21
Every edition of this story: Il fix di Siemens chiude falle ereditate nello SmartPlug