Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33892

24
FAUCET Score

CVE-2026-33892 is an authentication bypass vulnerability affecting multiple versions of Siemens Industrial Edge Management products (Pro V1, Pro V2, and Virtual editions). The flaw allows unauthenticated remote attackers to circumvent user authentication mechanisms and impersonate legitimate users by exploiting improper authentication enforcement on remote device connections. Successful exploitation requires the attacker to identify specific connection headers and ports while remote connection features are enabled. The vulnerability carries a HIGH severity rating with a CVSS score of 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), indicating an attack achievable over the network with low complexity and no user privileges required. The attack vector demonstrates low attack complexity and results in potential confidentiality, integrity, and availability impacts through tunneling to affected devices. However, device-level security controls such as application-specific authentication remain unaffected by this vulnerability. There is currently no evidence of active exploitation, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on security hot lists. The EPSS score of 0.000990000 indicates this CVE has received minimal community attention relative to other published vulnerabilities. No publicly available exploit code has been reported at this time, though the moderate FAUCET Risk Score of 46.0/100 warrants prompt patching of affected systems.

Impacted Technologies

VendorProductVersion(s)CPE
SiemensIndustrial Edge Management Pro V1
>= V1.7.6, < V1.15.17CNA affecteddefault unknown
SiemensIndustrial Edge Management Pro V2
>= V2.0.0, < V2.1.1CNA affecteddefault unknown
SiemensIndustrial Edge Management Virtual
>= V2.2.0, < V2.8.0CNA affecteddefault unknown

CVSS Data

CVSS version used by this source: 4.0

5.1MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 11th percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

cert-portal.siemens.com / productcert/html/ssa-609469.html