Full Report
Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: SICAM A8000 Device firmware CPCI85 for CP-8031/CP-8050 SICORE for CP-8010/CP-8012 SICAM EGS Device firmware CPCI85 SICAM S8000 SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions.
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in Siemens SICAM 8 Products
## CVE Details
- **CVE ID:** CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801
- **CVSS Score:**
- Max CVSS v3.1: 7.2 (High)
- Max CVSS v4.0: 8.6 (High)
- **CWE:**
- CWE-489 (Active Debug Code)
- CWE-1188 (Insecure Default)
- CWE-620 (Unverified Password Change)
## Affected Systems
- **Products:**
- **CPCI85 Firmware:** Used in SICAM A8000 (CP-8031/CP-8050) and SICAM EGS.
- **SICORE Firmware:** Used in SICAM A8000 (CP-8010/CP-8012) and SICAM S8000.
- **Versions:**
- CPCI85: All versions < V26.20
- SICORE: All versions < V26.20.0
- **Configurations:** Systems utilizing web-based management, OPC UA communication, or firmware update features.
## Vulnerability Description
Four distinct vulnerabilities affect the SICAM 8 product line:
1. **CVE-2026-54798:** An active debugging interface accessible via HTTP. Authenticated attackers can crash the web process.
2. **CVE-2026-54799:** Flaw in firmware signature validation. Allows the installation of malicious firmware, enabling persistent code execution.
3. **CVE-2026-54800:** Insecure default configuration where OPC UA security mechanisms are disabled, allowing unauthorized system control.
4. **CVE-2026-54801:** Insufficient validation during administrative credential modification via Web API, allowing privilege escalation.
## Exploitation
- **Status:** Not exploited (No reports of active exploitation or public PoC in the advisory).
- **Complexity:** Low to High (Variable depending on the specific CVE).
- **Attack Vector:**
- **Network:** CVE-2026-54798, CVE-2026-54800, CVE-2026-54801.
- **Local:** CVE-2026-54799 (Firmware updates).
## Impact
- **Confidentiality:** High (Potential for full system compromise and data access).
- **Integrity:** High (Unauthorized configuration changes and malicious firmware installation).
- **Availability:** High (Denial of Service via web process crashes).
## Remediation
### Patches
Siemens recommends updating to the following versions or later:
- **CPCI85:** Update to **V26.20** (Bundled in CP-8031/CP-8050 Package V26.20 or SICAM EGS Package V26.20).
- **SICORE:** Update to **V26.20.0** (Bundled in CP-8010/CP-8012 Package V26.20 or SICAM S8000 Package V26.20).
### Workarounds
- **Network Segmentation:** Protect network access with firewalls, VPNs, and VLAN segmentation.
- **Access Control:** Restrict access to the web management interface and OPC UA ports.
- **Manual Hardening:** Manually enable OPC UA security mechanisms if the default is set to "None" (mitigates CVE-2026-54800).
- **Operational Guidelines:** Adhere to Siemens grid security guidelines.
## Detection
- **Indicators of Compromise:** Unexpected reboots or crashes of the web management interface; unauthorized changes to administrative account credentials; presence of unsigned or unrecognized firmware versions.
- **Detection methods:** Monitor HTTP traffic for debugging endpoint access; audit administrative account logs via the Web API.
## References
- **Vendor Advisory:** hxxps://cert-portal.siemens[.]com/productcert/html/ssa-229470.html
- **Siemens Grid Security:** hxxps://www.siemens[.]com/gridsecurity
- **Siemens ProductCERT:** hxxps://www.siemens[.]com/cert/advisories