CVE-2026-50093 Details
Description
A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this vulnerability could allow an attacker to gain root access on the host system, potentially leading to a full compromise of the affected OIS environment.
A vulnerability exists in the Open Interface Services (OIS) web module of Siemens Siveillance Control Pro V3.0 (all versions prior to V3.0.12.2173), Siveillance Control Pro V4.0 (all versions prior to V4.0.9.2178), Siveillance Control V3.0 (all versions prior to V3.0.22.2177), and Siveillance Control V4.0 (all versions prior to V4.0.11.2177). This vulnerability allows attackers to upload arbitrary files to the server. Exploitation of this issue could result in root access on the host system, potentially leading to a complete compromise of the affected OIS environment.
Siemens has released patches and updates for Siveillance OIS. Users are advised to update to the latest versions. For specific product remediations, refer to the Siemens Security Advisory SSA-254516.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-254516.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Siemens Siveillance Control Pro | < V3.0.12.2173 |
CPE
Remediation
| |
| Siemens Siveillance Control | < V3.0.22.2177 < V4.0.11.2177 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion