Vulnerabilities · 55 days ago

SmartPlug Update Closes Inherited Wireless Flaws

The risk is not just a vulnerable plug. The real issue is that Siemens' smart plug inherits flaws from bundled wireless and authentication components, so an unpatched unit can weaken bootstrapping and access control inside an OT environment.

CISA says SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple component vulnerabilities, including CVE-2022-23303 and CVE-2019-9494, with OpenSSL, OpenSSH, and other packages named in the advisory. Siemens has released V7.26.0310 and CISA points operators to that version as the fix.

For critical manufacturing sites, the practical question is patch status, not just device firmware version. A plug that looks like simple power hardware can still carry inherited trust flaws in the wireless stack that matter to device onboarding and authentication.

CVE-2019-9494

NVD KEV

CVSS 5.9 MEDIUM: the implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. EPSS 4% (89th percentile).

CVE-2022-23303

NVD KEV

CVSS 9.8 CRITICAL: the implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. EPSS 3% (86th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-07-21

Editions

Related stories