HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical CVE‑2022‑23303 & CVE‑2019‑9494 Flaws in Siemens SIDIS Secured SmartPlug Expose Industrial Control Systems

Siemens SIDIS Secured SmartPlug firmware before V7.26.0310 contains several critical vulnerabilities (CVSS 9.8) that allow message‑integrity bypass, buffer overflows and side‑channel attacks. Enterprises must patch quickly and map the gaps to SOC 2 controls to maintain audit readiness.

LiveThreat™ Intelligence · 📅 July 21, 2026· 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

Critical Vulnerabilities (CVE‑2022‑23303, CVE‑2019‑9494) in Siemens SIDIS Secured SmartPlug Threaten Industrial Control Integrity

What It Is — Siemens SIDIS Secured SmartPlug firmware versions prior to V7.26.0310 contain multiple high‑severity flaws across OpenSSL, OpenSSH and related libraries, including improper message‑integrity enforcement, nonce reuse, buffer overflows, integer overflows, and a side‑channel timing leak.

Exploitability — CVSS v3.1 base score 9.8 (Critical). Public proof‑of‑concept code exists for the side‑channel (CVE‑2022‑23303); other flaws are remotely exploitable with crafted packets. No confirmed active exploitation has been reported, but the attack surface is broad.

Affected Products — Siemens SIDIS Secured SmartPlug (all versions < 7.26.0310).

Why It Matters for Compliance & Audit Readiness

  • Control‑mapping gaps – The vulnerabilities bypass authentication and integrity checks, directly violating SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations).
  • Continuous evidence – Demonstrating timely patching and configuration validation provides the audit‑ready evidence required for a defensible SOC 2 audit.
  • Vendor‑managed OT assets – Many enterprises rely on third‑party industrial devices; unmonitored security posture can break SOC 2 CC1.1 (Risk‑Based Vendor Management).

Recommended Actions

  • Inventory all SIDIS SmartPlug instances and verify firmware versions.
  • Deploy Siemens’ patch to V7.26.0310 or later immediately.
  • Map the affected controls (access control, change management, system monitoring) in your compliance framework and capture patch‑deployment logs as audit evidence.
  • Integrate automated OT‑asset vulnerability scanning into your continuous compliance pipeline.

Source: CISA Advisory – ICSA‑26‑202‑04

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-04

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →