Executive brief
Siemens SICAM 8 power automation devices are affected by a security flaw in their administrative web interface. An attacker with existing high-level access could exploit this to modify account credentials without proper verification, potentially leading to full control over the device. This could impact the reliability and operation of critical electrical grid infrastructure.
Technical details
A vulnerability exists in the web API of Siemens CPCI85 and SICORE firmware used in SICAM 8 products. The application fails to sufficiently validate authentication credentials when processing administrative account modifications (CWE-620). An authenticated attacker with high privileges can exploit this flaw over the network to bypass security controls and gain further unauthorized elevated privileges or modify other administrative accounts. Siemens has released firmware version V26.20 (and V26.20.0 for SICORE) to remediate this issue.
Affected products
- Siemens CPCI85 Central Processing/Communication < V26.20
- Siemens SICORE Base system < V26.20.0
Timeline
- 2026-07-09: disclosed
- 2026-07-09: advisory
- 2026-07-09: patched