← Back to home
ICSA-26-134-01  ·  Published 2026-05-14  ·  View on CISA ICS-CERT ↗

Siemens gWAP

CVSS 8.0 HIGH

Risk Summary

Siemens gPROMS Web Applications Publisher (gWAP) is affected by a remote code execution vulnerability introduced through a third-party component, namely the Axios HTTP client library. The vulnerability stems from a specific "Gadget" attack chain that allows prototype pollution in other third-party libraries, potentially allowing an attacker to execute arbitrary code. Siemens has released a new version for gWAP and recommends to update to the latest version.

CVEs (1)

Remediations

  • Update to V3.1.1 or later version

Affected Vendors

Siemens

Affected Products (1)

Siemens · gWAP vers:intdot/<3.1.1

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more