CVE-2019-9494
CVSS 5.9 MEDIUM: the implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. EPSS 4% (89th percentile).
Vulnerabilities · 55 days ago
The risk is not just a vulnerable plug. The real issue is that Siemens' smart plug inherits flaws from bundled wireless and authentication components, so an unpatched unit can weaken bootstrapping and access control inside an OT environment.
CISA says SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple component vulnerabilities, including CVE-2022-23303 and CVE-2019-9494, with OpenSSL, OpenSSH, and other packages named in the advisory. Siemens has released V7.26.0310 and CISA points operators to that version as the fix.
For critical manufacturing sites, the practical question is patch status, not just device firmware version. A plug that looks like simple power hardware can still carry inherited trust flaws in the wireless stack that matter to device onboarding and authentication.
CVSS 5.9 MEDIUM: the implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. EPSS 4% (89th percentile).
CVSS 9.8 CRITICAL: the implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. EPSS 3% (86th percentile).
1 source covering this story
Siemens SIDIS Secured SmartPlug | CISA
Siemens SIDIS Secured SmartPlug Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below.
Part of the PlainSec briefing for 2026-07-21