Siemens Siveillance Control
A critical vulnerability (CVE-2026-50093) exists in Siemens Siveillance Control and Siveillance Control Pro, allowing an attacker to upload arbitrary files and potentially gain root access to the OIS server. Siemens has released patches to address this issue, and CISA recommends minimizing network exposure and isolating control systems from business networks to mitigate the risk of exploitation. Users are advised to update to the latest versions immediately.
Siemens Siveillance Control and Siveillance Control Pro are affected by a critical vulnerability, CVE-2026-50093, within the Open Interface Services (OIS) web module. This vulnerability enables an attacker to upload arbitrary files to the server, potentially leading to a full compromise of the affected OIS environment and root access on the host system. The vulnerability was reported by Siemens ProductCERT and has been addressed with vendor patches.
Affected products include Siveillance Control Pro V3.0 (versions prior to V3.0.12.2173), Siveillance Control Pro V4.0 (versions prior to V4.0.9.2178), Siveillance Control V3.0 (versions prior to V3.0.22.2177), and Siveillance Control V4.0 (versions prior to V4.0.11.2177).
CISA recommends implementing several defensive measures to reduce the risk of exploitation. These include minimizing network exposure to affected devices, isolating control systems from business networks, and utilizing more secure remote access methods such as VPNs, while recognizing that VPNs themselves can have vulnerabilities. Organizations should perform thorough impact analysis and risk assessments before deploying any defensive measures.
Siemens ProductCERT has provided detailed information and patches for this vulnerability. Users are strongly encouraged to update their systems to the latest versions immediately. For further inquiries, contact Siemens ProductCERT at https://www.siemens.com/cert/advisories.