{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]}],"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"Authentication is not configured by default for the Node-RED server on the Pilz industrial PC IndustrialPI. An unauthenticated remote attacker has full access to the Node-RED server and can run arbitrary operating system commands on the underlying operating system with privileged rights.","title":"Summary"},{"category":"description","text":"The attacker can not only view but create and alter flows in Node-RED. Flows can contain code blocks where commands are executed on the IndustrialPI itself. An attacker can use these code blocks to run any command as a privileged user on the IndustrialPI.","title":"Impact"},{"category":"description","text":"Consult our PDF with remediations which you can find under [https://www.pilz.com/search#currentPage=1&SEARCH=Security%20Advis.%20IndustrialPI%20Remediat.](https://www.pilz.com/search#currentPage=1&SEARCH=Security%20Advis.%20IndustrialPI%20Remediat.). In order to activate the authentication as described in the PDF, you have to have the Node-RED service enabled via the web application.","title":"Remediation"},{"category":"description","text":"Limit network access to the IndustrialPI by using a firewall or similar measures.","title":"Mitigation"}],"publisher":{"category":"vendor","contact_details":"security@pilz.com","name":"Pilz GmbH & Co. KG","namespace":"https://www.pilz.com"},"references":[{"category":"external","summary":"For further security-related issues in Pilz products please contact the Pilz Product Security Incident Response Team (PSIRT)","url":"https://www.pilz.com/security"},{"category":"external","summary":"CERT@VDE Security Advisories for Pilz GmbH & Co. KG","url":"https://certvde.com/en/advisories/vendor/pilz/"},{"category":"self","summary":"PPSA-2025-002: Pilz: Missing Authentication in Node-RED integration - HTML","url":"https://certvde.com/en/advisories/PPSA-2025-002/"},{"category":"self","summary":"PPSA-2025-002: Pilz: Missing Authentication in Node-RED integration - CSAF","url":"https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2025/ppsa-2025-002.json"}],"title":"Pilz: Missing Authentication in Node-RED integration","tracking":{"aliases":["VDE-2025-045","PPSA-2025-002"],"current_release_date":"2025-07-01T10:00:00.000Z","generator":{"date":"2025-06-26T09:07:18.730Z","engine":{"name":"Secvisogram","version":"2.5.26"}},"id":"PPSA-2025-002","initial_release_date":"2025-07-01T10:00:00.000Z","revision_history":[{"date":"2025-07-01T10:00:00.000Z","number":"1.0.0","summary":"Initial Version"}],"status":"final","version":"1.0.0"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"IndustrialPI 4","product":{"name":"IndustrialPI 4","product_id":"CSAFPID-11000","product_identification_helper":{"model_numbers":["A1000002","A1000003"]}}}],"category":"product_family","name":"Hardware"},{"branches":[{"branches":[{"category":"product_version_range","name":"<=2024-08","product":{"name":"Firmware Bullseye <=2024-08","product_id":"CSAFPID-21000"}}],"category":"product_name","name":"Bullseye"}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"Pilz"}],"relationships":[{"category":"installed_on","full_product_name":{"name":"Firmware Bullseye <=2024-08 installed on IndustrialPI 4","product_id":"CSAFPID-31000"},"product_reference":"CSAFPID-21000","relates_to_product_reference":"CSAFPID-11000"}]},"vulnerabilities":[{"cve":"CVE-2025-41656","cwe":{"id":"CWE-306","name":"Missing Authentication for Critical Function"},"notes":[{"category":"description","text":"An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default. \n","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-31000"]},"remediations":[{"category":"vendor_fix","details":"Consult our PDF with remediations which you can find under [www.pilz.com/downloads](https://www.pilz.com/search#currentPage=1&SEARCH=Security%20Advis.%20IndustrialPI%20Remediat.). In order to activate the authentication as described in the PDF, you have to have the Node-RED service enabled via the web application.","product_ids":["CSAFPID-31000"]},{"category":"mitigation","details":"Limit network access to the IndustrialPI by using a firewall or similar measures.","product_ids":["CSAFPID-31000"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":10,"environmentalSeverity":"CRITICAL","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","temporalScore":10,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31000"]}],"title":"CVE-2025-41656"}]}