CVE-2026-54800 Details
Description
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.
A vulnerability exists in Siemens SICAM 8 products, specifically in the CPCI85 Central Processing/Communication and SICORE Base system components, all versions prior to the respective V26.20 releases. The vulnerability arises because the applications are shipped with a default configuration that disables all OPC UA security mechanisms. This lack of security could enable an attacker to gain unauthorized access and control over critical system functions.
Users are advised to update to Siemens SICAM CPCI85 V26.20 or later, and SICORE V26.20.0 or later. The V26.20 update for CPCI85 is available within the 'CP-8031/CP-8050 Package' and the 'SICAM EGS Package'. For SICORE, the V26.20.0 update can be found in the 'CP-8010/CP-8012 Package' and the 'SICAM S8000 Package'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-229470.html | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1188 | Initialization of a Resource with an Insecure Default | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |