Executive brief
Siemens SICAM 8 power automation devices are affected by a security flaw where the default configuration disables all security protections for the OPC UA communication protocol. This component is used to manage communications in critical power grid infrastructure. An attacker could exploit this to gain unauthorized access and control over critical system functions, potentially impacting the reliability of power grid operations.
Technical details
The vulnerability (CWE-1188) exists in the default initialization of the OPC UA interface within Siemens CPCI85 and SICORE firmware. The application ships with a configuration that disables all OPC UA security mechanisms by default. A remote attacker can exploit this over the network to gain unauthorized access and control over critical system functions. While the attack requires high complexity (AC:H), it requires no authentication or user interaction. Siemens has released firmware updates (V26.20/V26.20.0) to address this issue and recommends following general security guidelines for protecting industrial network access.
Affected products
- Siemens CPCI85 Central Processing/Communication All versions < V26.20
- Siemens SICORE Base system All versions < V26.20.0
Timeline
- 2026-07-09: disclosed: Initial publication of SSA-229470 by Siemens ProductCERT
- 2026-07-09: patched: Fixes released in CPCI85 V26.20 and SICORE V26.20.0