IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-254516: Arbitrary File Upload in OIS Web Module

CRITICAL
CVSS 9.0
Date 2026-09-08T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-50093 9.0 critical
CVE-2026-50093. A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this vulnerability could allow an attacker to gain root access on the host system, potentially leading to a full compromise of the affected OIS environment.

// Remediations (4)

Patch: Update to V3.0.12.2173 or later version
Update to V3.0.12.2173 or later version
Patch: Update to V3.0.22.2177 or later version
Update to V3.0.22.2177 or later version
Patch: Update to V4.0.11.2177 or later version
Update to V4.0.11.2177 or later version
Patch: Update to V4.0.9.2178 or later version
Update to V4.0.9.2178 or later version

// References