news.mlab.sh
Back to the feed
threat-intel

Siemens SICAM 8

High
Summary

Siemens has released security advisories detailing multiple vulnerabilities in its SICAM 8 industrial control system firmware and related components. These vulnerabilities could allow an attacker to cause denial of service, execute malicious firmware, and gain unauthorized access to critical system functions. Siemens recommends immediate updates to the affected products to mitigate these risks.

Siemens has identified and reported several vulnerabilities within its SICAM 8 industrial control system, impacting a range of products including the SICAM A8000 Device firmware, CPCI85 Central Processing/Communication, SICORE Base system, and SICAM EGS Device firmware. These vulnerabilities could be exploited to disrupt system operations, potentially leading to denial of service conditions. A key issue is a debugging interface accessible via HTTP endpoints, which could be leveraged to crash the web process. Furthermore, the firmware update mechanism’s signature validation process is vulnerable, allowing attackers to install malicious firmware and achieve persistent code execution. The application ships with a default configuration that disables all OPC UA security mechanisms, creating an opportunity for unauthorized access and control. Finally, insufficient validation of authentication credentials during administrative account modifications through the web API could bypass security controls and grant elevated privileges. Siemens strongly recommends that operators of critical power systems worldwide immediately apply the provided security updates using the documented procedures. They also advise minimizing network exposure for control system devices and implementing robust network segmentation and VPN solutions to further protect against exploitation.

Read the full article at CISA Advisories