Siemens SICAM 8

Plan PatchCVSS 7.2ICS-CERT ICSA-26-197-05Jul 9, 2026
Siemens
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityLow
User InteractionNone needed
Summary

Multiple vulnerabilities in SICAM 8 products (CPCI85 Central Processing/Communication module and SICORE Base system) before version V26.20/V26.20.0 can lead to denial of service attacks. These vulnerabilities are identified by CWE-489 (disabling security logging), CWE-1188 (insecure defaults), and CWE-620 (unvalidated input). The CPCI85 module is used in CP-8031/CP-8050 communication processors and SICAM EGS device firmware. The SICORE module is used in CP-8010/CP-8012 communication processors and SICAM S8000 systems. Siemens has released firmware updates addressing all vulnerabilities.

What this means
What could happen
Multiple denial of service vulnerabilities in SICAM 8 control and communication modules could allow an authenticated attacker to disrupt grid stability monitoring and substation automation by crashing the central processing unit or preventing normal communication between devices.
Who's at risk
This affects utilities and industrial facilities using Siemens SICAM 8 substation automation and communication platforms. Specific equipment impacted includes CPCI85 Central Processing/Communication modules in CP-8031, CP-8050, and SICAM EGS systems, and SICORE Base system modules in CP-8010, CP-8012, and SICAM S8000 configurations. Organizations managing grid monitoring, protection relay coordination, and substation data concentration should prioritize updates.
How it could be exploited
An attacker with engineering credentials could send specially crafted commands or data to the CPCI85 or SICORE modules over the network, triggering a denial of service condition that causes the device to stop processing or communicating until manually restarted.
Prerequisites
  • Network access to CPCI85 or SICORE module management port
  • Valid engineering workstation credentials or privileged user access
  • Affected firmware version (CPCI85 before V26.20 or SICORE before V26.20.0) running on the target device
remotely exploitablerequires high privilege level (engineering credentials)affects core communications and control infrastructurevendor patches are available
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
CPCI85 Central Processing/Communication < V26.20< 26.2026.20
SICORE Base system < V26.20.0< 26.20.026.20.0
Remediation & Mitigation
0/5
Do now
0/1
HARDENINGRestrict network access to CPCI85 and SICORE management interfaces to authorized engineering workstations only using firewall rules
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

HOTFIXUpdate CPCI85 firmware to version V26.20 or later within CP-8031/CP-8050 Package
HOTFIXUpdate CPCI85 firmware to version V26.20 or later within SICAM EGS Package
HOTFIXUpdate SICORE firmware to version V26.20.0 or later within CP-8010/CP-8012 Package
HOTFIXUpdate SICORE firmware to version V26.20.0 or later within SICAM S8000 Package
API: /api/v1/advisories/f72e59f0-40c8-4348-862a-2379c95d73af

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Siemens SICAM 8 | CVSS 7.2 - OTPulse