Junglewise Threat Intelligence

CVE-2026-54798: Siemens SICAM 8 active debug code in CPCI85 and SICORE firmware

CVE-2026-54798 · Severity: medium · CVSS 6.5 · Published 2026-07-09

Technologies: Siemens SICORE Base system, Siemens CPCI85 Central Processing/Communication. Vendors: Siemens.

Executive brief

Siemens SICAM 8 power automation devices contain a debugging interface that was unintentionally left active in production firmware. An authenticated user could access this interface via the web to crash the device's web service, leading to a denial-of-service condition. This could disrupt the ability of operators to manage or monitor critical power grid infrastructure.

Technical details

This vulnerability is classified as Active Debug Code (CWE-489) within the CPCI85 and SICORE firmware components. The affected software exposes a debugging interface through HTTP endpoints that should not be accessible in production environments. An attacker with low-privileged network access can interact with these endpoints to trigger a crash of the web process. This results in a denial-of-service (DoS) condition for the web-based management interface. Siemens has addressed this in CPCI85 version V26.20 and SICORE version V26.20.0.

Affected products

  • Siemens CPCI85 Central Processing/Communication All versions < V26.20
  • Siemens SICORE Base system All versions < V26.20.0
  • Siemens SICAM A8000 CP-8031/CP-8050 Firmware versions < V26.20
  • Siemens SICAM A8000 CP-8010/CP-8012 Firmware versions < V26.20.0
  • Siemens SICAM EGS Firmware versions < V26.20
  • Siemens SICAM S8000 Firmware versions < V26.20.0

Timeline

  • 2026-07-09: advisory: Initial publication of SSA-229470 by Siemens ProductCERT
  • 2026-07-09: patched: Fixes released in version V26.20 / V26.20.0

References

Related threats