CVE-2026-54799 Details
Description
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.
A vulnerability exists in Siemens SICAM 8 products, specifically in the CPCI85 Central Processing/Communication application, all versions prior to V26.20. The issue arises in the firmware update mechanism, where the signature validation process is flawed. This vulnerability could enable an attacker to install malicious firmware, resulting in persistent code execution and compromising the system.
Users are advised to update to SICAM CPCI85 V26.20 or later. The V26.20 firmware is available within the 'CP-8031/CP-8050 Package' V26.20 and the 'SICAM EGS Package' V26.20.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-229470.html | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-489 | Active Debug Code | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |