Siemens SICAM 8 Multiple Vulnerabilities (Active Debug Code, Insecure OPC UA Defaults, Unverified Password Change)
First seen Jul 17, 2026 · Updated Jul 17, 2026 · CVSS 7.2
Siemens has disclosed four vulnerabilities affecting SICAM 8 product firmware (CPCI85 and SICORE base systems) used in energy and critical manufacturing environments. The flaws include an exposed debugging interface, insufficient firmware update signature validation, insecure default OPC UA security settings, and unverified password changes, which combined could lead to denial of service, unauthorized access, or persistent code execution on affected devices. Siemens has released firmware updates (V26.20/V26.20.0) to remediate all four issues.
Technical Analysis
CVE-2026-54798 (CVSS 6.5) exposes an active debugging interface via HTTP that an authenticated attacker can use to crash the web process (CWE-489). CVE-2026-54799 (CVSS 6.7) involves insufficient firmware update signature validation, potentially enabling installation of malicious firmware and persistent code execution. CVE-2026-54800 (CVSS 4.8) stems from OPC UA shipping with all security mechanisms disabled by default (CWE-1188), allowing unauthorized access to critical system functions. CVE-2026-54801 (CVSS 7.2, HIGH) is an unverified password change flaw (CWE-620) in the web API that lets an authenticated attacker bypass validation and escalate privileges. These are OT/ICS firmware vulnerabilities in Siemens SICAM 8 devices deployed in energy grid protection and automation systems; there is no direct AI agent system impact, as these are embedded industrial control device firmware issues rather than components used in LLM/agent tool chains or software supply chains.
Affected Systems
Siemens SICAM 8 products: CPCI85 Central Processing/Communication (CP-8031/CP-8050) firmware versions intdot < 26.20; SICORE Base system (CP-8010/CP-8012, SICAM S8000) firmware versions intdot < 26.20.0; SICAM A8000 and SICAM EGS device firmware using CPCI85.
Indicators of Compromise
- No specific IOCs published; this is a vendor-disclosed vulnerability advisory, not an active exploitation campaign.
Remediation Steps
- 1
Update CPCI85 firmware
Update to CPCI85 V26.20 or later, available within the 'CP-8031/CP-8050 Package' V26.20 and 'SICAM EGS Package' V26.20 from Siemens Industry Support.
- 2
Update SICORE firmware
Update to SICORE V26.20.0 or later, available within the 'CP-8010/CP-8012 Package' V26.20 and 'SICAM S8000 Package' V26.20 from Siemens Industry Support.
- 3
Network segmentation
Isolate ICS/OT networks and devices behind firewalls, segment from business networks, and minimize internet exposure of control system devices.
- 4
Secure remote access
Use VPNs for remote access where required, keeping VPN software updated, and recognize VPN security depends on connected endpoint security.
- 5
Validate updates before deployment
Test and validate firmware updates in a controlled environment prior to production rollout, with supervision by trained staff.
- 6
Review OPC UA configuration
Explicitly enable and configure OPC UA security mechanisms rather than relying on insecure defaults.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.