Executive brief
Siemens Siveillance Control is a critical surveillance management platform used to protect and monitor facilities in manufacturing, communications, and commercial sectors worldwide. An arbitrary file upload vulnerability in the OIS (Open Interface Services) web module allows authenticated attackers to upload malicious files and gain root-level system access. A successful exploit could result in complete takeover of the surveillance infrastructure, enabling attackers to disable monitoring, manipulate recordings, or pivot into connected networks.
Technical details
CWE-434 (Unrestricted Upload of File with Dangerous Type) exists in the OIS web module, allowing authenticated users with low privileges to upload arbitrary files without proper validation. The attack requires adjacent network access and authenticated credentials (PR:L), but does not require user interaction (UI:N) and impacts confidentiality, integrity, and availability across the system scope (S:C). Successful file upload can be leveraged to execute code with root privileges, enabling complete host compromise. Siemens has released patches: Siveillance Control Pro V3.0 update to ≥3.0.12.2173, Pro V4.0 update to ≥4.0.9.2178, Control V3.0 update to ≥3.0.22.2177, and Control V4.0 update to ≥4.0.11.2177.
Affected products
- Siemens Siveillance Control Pro V3.0 < 3.0.12.2173
- Siemens Siveillance Control Pro V4.0 < 4.0.9.2178
- Siemens Siveillance Control V3.0 < 3.0.22.2177
- Siemens Siveillance Control V4.0 < 4.0.11.2177
Timeline
- 2026-09-08: disclosed
- 2026-09-22: advisory: CISA republication of Siemens ProductCERT SSA-254516