CVE-2026-33892 is an authentication bypass vulnerability affecting multiple versions of Siemens Industrial Edge Management products (Pro V1, Pro V2, and Virtual editions). The flaw allows unauthenticated remote attackers to circumvent user authentication mechanisms and impersonate legitimate users by exploiting improper authentication enforcement on remote device connections. Successful exploitation requires the attacker to identify specific connection headers and ports while remote connection features are enabled. The vulnerability carries a HIGH severity rating with a CVSS score of 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), indicating an attack achievable over the network with low complexity and no user privileges required. The attack vector demonstrates low attack complexity and results in potential confidentiality, integrity, and availability impacts through tunneling to affected devices. However, device-level security controls such as application-specific authentication remain unaffected by this vulnerability. There is currently no evidence of active exploitation, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on security hot lists. The EPSS score of 0.000990000 indicates this CVE has received minimal community attention relative to other published vulnerabilities. No publicly available exploit code has been reported at this time, though the moderate FAUCET Risk Score of 46.0/100 warrants prompt patching of affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Siemens | Industrial Edge Management Pro V1 | >= V1.7.6, < V1.15.17CNA affecteddefault unknown | |
| Siemens | Industrial Edge Management Pro V2 | >= V2.0.0, < V2.1.1CNA affecteddefault unknown | |
| Siemens | Industrial Edge Management Virtual | >= V2.2.0, < V2.8.0CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.