Critical Vulnerabilities (CVE‑2022‑23303, CVE‑2019‑9494) in Siemens SIDIS Secured SmartPlug Threaten Industrial Control Integrity
What It Is — Siemens SIDIS Secured SmartPlug firmware versions prior to V7.26.0310 contain multiple high‑severity flaws across OpenSSL, OpenSSH and related libraries, including improper message‑integrity enforcement, nonce reuse, buffer overflows, integer overflows, and a side‑channel timing leak.
Exploitability — CVSS v3.1 base score 9.8 (Critical). Public proof‑of‑concept code exists for the side‑channel (CVE‑2022‑23303); other flaws are remotely exploitable with crafted packets. No confirmed active exploitation has been reported, but the attack surface is broad.
Affected Products — Siemens SIDIS Secured SmartPlug (all versions < 7.26.0310).
Why It Matters for Compliance & Audit Readiness
- Control‑mapping gaps – The vulnerabilities bypass authentication and integrity checks, directly violating SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations).
- Continuous evidence – Demonstrating timely patching and configuration validation provides the audit‑ready evidence required for a defensible SOC 2 audit.
- Vendor‑managed OT assets – Many enterprises rely on third‑party industrial devices; unmonitored security posture can break SOC 2 CC1.1 (Risk‑Based Vendor Management).
Recommended Actions
- Inventory all SIDIS SmartPlug instances and verify firmware versions.
- Deploy Siemens’ patch to V7.26.0310 or later immediately.
- Map the affected controls (access control, change management, system monitoring) in your compliance framework and capture patch‑deployment logs as audit evidence.
- Integrate automated OT‑asset vulnerability scanning into your continuous compliance pipeline.
Source: CISA Advisory – ICSA‑26‑202‑04