Junglewise Threat Intelligence

CVE-2026-54799: Siemens CPCI85 and SICORE firmware signature validation bypass

CVE-2026-54799 · Severity: medium · CVSS 6.7 · Published 2026-07-09

Technologies: Siemens SICORE Base system, Siemens CPCI85 Central Processing/Communication. Vendors: Siemens.

Executive brief

Siemens CPCI85 and SICORE firmware, used in industrial automation and power grid control devices, contain a flaw in how they verify software updates. An attacker with high-level system access could bypass security checks to install unauthorized, malicious firmware. This could result in permanent control over the device, potentially disrupting critical infrastructure operations or compromising sensitive industrial data.

Technical details

A vulnerability exists in the firmware update mechanism's signature validation process within Siemens CPCI85 (used in SICAM A8000 and EGS) and SICORE (used in SICAM A8000 and S8000). The root cause is related to improper validation of cryptographic signatures during the update process, categorized under CWE-489. An attacker with administrative or high-privileged local access (PR:H) can exploit this to bypass integrity checks and install modified firmware. Successful exploitation leads to persistent, unauthorized code execution with full system privileges. Siemens has released firmware version V26.20 (and V26.20.0 for SICORE) to remediate this issue.

Affected products

  • Siemens CPCI85 Central Processing/Communication All versions < V26.20
  • Siemens SICORE Base system All versions < V26.20.0

Timeline

  • 2026-07-09: disclosed: Initial publication of SSA-229470 by Siemens ProductCERT
  • 2026-07-09: patched: Firmware versions V26.20 / V26.20.0 released to address the vulnerability

References

Related threats