Arbitrary File Upload in OIS Web Module

Plan PatchCVSS 9SSA-254516Sep 8, 2026
Siemens
Attack path
Attack VectorAdjacent
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A vulnerability in the Open Interface Services (OIS) web module affects Siveillance Control and Siveillance Control Pro versions 3.x and 4.x. An attacker can upload arbitrary files to the server, potentially gaining unauthorized root-level access to the OIS system.

What this means
What could happen
An attacker with access to the OIS web interface could upload malicious files to gain root-level control of the Siveillance server, allowing them to alter video surveillance configurations, delete footage, or disrupt security system operations.
Who's at risk
This affects organizations running Siemens Siveillance Control or Siveillance Control Pro as their video surveillance and physical access control system. Security teams and facility managers relying on these systems for camera monitoring, recording, and facility access decisions should prioritize patching.
How it could be exploited
An attacker with network access to the OIS web module authenticates with valid credentials, then uploads a malicious file through the web interface. The file is processed by the server with root privileges, giving the attacker full system control over the video surveillance and access control systems running on that server.
Prerequisites
  • Network access to the OIS web module (typically port 80/443)
  • Valid user credentials (login required)
  • Access to a file upload interface within the web application
Remotely exploitable via web interfaceAuthentication required (reduces but does not eliminate risk)Low complexity attackHigh CVSS score (9.0)Affects security infrastructure (surveillance system)Root-level compromise potential
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (4)
4 with fix
ProductAffected VersionsFix Status
Siveillance Control Pro V3.0 < V3.0.12.2173< 3.0.12.21733.0.12.2173
Siveillance Control Pro V4.0 < V4.0.9.2178< 4.0.9.21784.0.9.2178
Siveillance Control V3.0 < V3.0.22.2177< 3.0.22.21773.0.22.2177
Siveillance Control V4.0 < V4.0.11.2177< 4.0.11.21774.0.11.2177
Remediation & Mitigation
0/6
Do now
0/2
WORKAROUNDRestrict network access to the OIS web module to authorized staff only using firewall rules or network segmentation
HARDENINGEnforce strong, unique passwords for all OIS user accounts and disable any default credentials
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Siveillance Control Pro to version 3.0.12.2173 or later
HOTFIXUpdate Siveillance Control Pro to version 4.0.9.2178 or later
HOTFIXUpdate Siveillance Control to version 3.0.22.2177 or later
HOTFIXUpdate Siveillance Control to version 4.0.11.2177 or later
API: /api/v1/advisories/c5cbf830-8a07-4fe4-8859-33f215d53888

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Arbitrary File Upload in OIS Web Module | CVSS 9 - OTPulse