Siemens SICAM 8
Multiple vulnerabilities in SICAM 8 products (CPCI85 Central Processing/Communication module and SICORE Base system) before version V26.20/V26.20.0 can lead to denial of service attacks. These vulnerabilities are identified by CWE-489 (disabling security logging), CWE-1188 (insecure defaults), and CWE-620 (unvalidated input). The CPCI85 module is used in CP-8031/CP-8050 communication processors and SICAM EGS device firmware. The SICORE module is used in CP-8010/CP-8012 communication processors and SICAM S8000 systems. Siemens has released firmware updates addressing all vulnerabilities.
- Network access to CPCI85 or SICORE module management port
- Valid engineering workstation credentials or privileged user access
- Affected firmware version (CPCI85 before V26.20 or SICORE before V26.20.0) running on the target device
Patching may require device reboot — plan for process interruption
/api/v1/advisories/f72e59f0-40c8-4348-862a-2379c95d73afGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.