Full Report
[Control systems] Siemens security advisory (AV26-802)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in Siemens Control Systems and Engineering Software (AV26-802)
## CVE Details
*Note: The source article provides a summary of affected products for August 11, 2026, but does not list individual CVE IDs. Based on the product list, these typically involve memory corruption (Parasolid/Solid Edge) and improper input validation (Desigo/LOGO!).*
- **CVE ID:** Multiple (See Siemens CERT for specific IDs)
- **CVSS Score:** Range 7.8 - 9.8 (Estimated based on product types)
- **Severity:** High to Critical
- **CWE:** Commonly includes CWE-119 (Memory Corruption), CWE-20 (Improper Input Validation), and CWE-287 (Improper Authentication).
## Affected Systems
- **Products & Versions:**
- **Desigo DXR2 / PXC3:** Prior to V01.21.233.16-7862
- **Desigo PXC4 / PXC5 / PXC7:** Prior to V02.21.194.36-2715
- **LOGO! Soft Comfort:** Prior to V9
- **Parasolid V38.0:** Prior to V38.0.235
- **Parasolid V38.1:** Prior to V38.1.230
- **SIMATIC IoT2050 Advanced:** Prior to V4.3.4.1
- **Siemens License Server (SLS):** Prior to V5.1 and V5.3
- **Simcenter Femap:** Prior to V2606.0001
- **Simcenter Nastran:** Prior to V2606
- **Solid Edge SE2025:** Prior to V225.0 Update 15
- **Solid Edge SE2026:** Prior to V226.0 Update 7
## Vulnerability Description
This advisory covers a broad range of Siemens products. The vulnerabilities generally fall into two categories:
1. **Industrial Control/IoT (Desigo, SIMATIC, LOGO!):** Likely involve network-based vulnerabilities such as Denial of Service (DoS) or remote code execution via malformed packets.
2. **PLM/Engineering Software (Parasolid, Solid Edge, Simcenter):** These typically involve file-parsing vulnerabilities where opening a specially crafted CAD or simulation file leads to memory corruption and arbitrary code execution.
## Exploitation
- **Status:** Not exploited (No current reports of active exploitation in the wild).
- **Complexity:** Low to Medium.
- **Attack Vector:**
- **Network:** For Desigo and SIMATIC IoT devices.
- **Local/User Interaction:** For Solid Edge and Simcenter (requires a user to open a malicious file).
## Impact
- **Confidentiality:** High (Potential for data exfiltration and intellectual property theft).
- **Integrity:** High (Potential for unauthorized modification of control logic or engineering designs).
- **Availability:** High (Potential for system crashes or operational downtime in building automation).
## Remediation
### Patches
Siemens recommends updating to the following versions or newer:
- **Desigo Series:** V01.21.233.16-7862 or V02.21.194.36-2715 (Product dependent).
- **LOGO! Soft Comfort:** V9.
- **Parasolid:** V38.0.235 / V38.1.230.
- **SIMATIC IoT2050:** V4.3.4.1.
- **Siemens License Server:** V5.1 / V5.3.
- **Simcenter:** V2606 / V2606.0001.
- **Solid Edge:** SE2025 Update 15 / SE2026 Update 7.
### Workarounds
- **Network Segmentation:** Isolate Desigo and SIMATIC devices from the internet and untrusted office networks.
- **Least Privilege:** Ensure users running engineering software do not have administrative privileges.
- **File Validation:** Exercise caution when opening CAD files from untrusted or external sources.
## Detection
- **Indicators of Compromise:** Unexpected system reboots, unusual outbound network traffic from IoT gateways, or application crashes when opening specific project files.
- **Detection methods:** Use Siemens-specific industrial security tools or general Intrusion Detection Systems (IDS) with signatures for Siemens communication protocols (S7, BACnet).
## References
- Siemens CERT Services: hxxps[://]www[.]siemens[.]com/en-us/content/cert-services/
- Canadian Centre for Cyber Security Advisory: hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-802