Siemens SIDIS Secured SmartPlug Plagued by Multiple Critical Vulnerabilities
Siemens' SIDIS Secured SmartPlug is affected by several critical vulnerabilities, including arbitrary code execution and data compromise risks, stemming from issues in core components like OpenSSL and OpenSSH.

Siemens has issued a critical advisory for its SIDIS Secured SmartPlug device, detailing multiple vulnerabilities that could allow attackers to execute arbitrary code, compromise data, and disrupt operations. The affected versions are those prior to V7.26.0310, impacting deployments worldwide across critical manufacturing sectors.
The vulnerabilities stem from weaknesses in several fundamental components, including OpenSSL, OpenSSH, and other integrated packages. Specifically, CVE-2022-23303 and CVE-2022-23304 highlight issues within the SAE and EAP-pwd implementations in hostapd and wpa_supplicant, related to side-channel attacks due to cache access patterns. These flaws, noted as incomplete fixes for previous CVEs, can lead to significant security compromises.
Further complicating the security posture, CVE-2022-37660 involves a vulnerability in hostapd where the PKEX code remains active post-association, allowing past attackers to potentially subvert future associations by observing and manipulating public keys. This could lead to the compromise of the ephemeral public key, a critical element in secure communication.
Additional critical flaws include CVE-2022-48174, an out-of-bounds write vulnerability in busybox's ash.c, which could enable arbitrary code execution, particularly noted in the context of Internet of Vehicles deployments. This vulnerability carries a CVSS score of 7.8 and is rated as HIGH severity.
The advisory also lists CVE-2025-5222, a stack buffer overflow in the ICU library's genrb binary, which could lead to memory corruption and local arbitrary code execution. Another significant vulnerability, CVE-2025-5914, found in the libarchive library, involves an integer overflow that can result in a double-free condition, potentially leading to arbitrary code execution or denial-of-service.
Siemens has released an update to version V7.26.0310 to address these vulnerabilities. The company strongly recommends that all users update their SIDIS Secured SmartPlug devices to the latest version to mitigate these risks. The vulnerabilities collectively carry CVSS scores up to 9.8, indicating a CRITICAL severity.
These vulnerabilities underscore the persistent challenges in securing embedded systems and industrial control devices, where reliance on third-party libraries and components can introduce complex attack surfaces. The wide-ranging nature of the flaws, from cryptographic weaknesses to buffer overflows, highlights the need for continuous vigilance and prompt patching in operational technology environments.