Siemens SICAM 8
View CSAF Summary Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens SICAM 8 are affected: CPCI85 Central Processing/Communication vers:intdot/<26.20 (CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801) SICORE Base system vers:intdot/<26.20.0 (CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801) CVSS Vendor Equipment Vulnerabilities v3 7.2 Siemens Siemens SICAM 8 Active Debug Code, Initialization of a Resource with an Insecure Default, Unverified Password Change Background Critical Infrastructure Sectors: Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-54798 The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions. View CVE Details Affected Products Siemens SICAM 8 Vendor: Siemens Product Version: CPCI85 Central Processing/Communication < V26.20, SICORE Base system < V26.20.0 Product Status: known_affected Remediations Vendor fix Update to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/ Vendor fix Update to V26.20.0 or later version The firmware SICORE V26.20.0 is present within “CP-8010/CP-8012 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109972894/ and also within “SICAM S8000 Package” V26.20 htt
CSIRTS triage
- What
- Multiple vulnerabilities could lead to denial of service.
- Who is affected
- Multiple SICAM 8 products including CPCI85 and SICORE with versions below 26.20.
- Urgency
- Remediation is urgent due to the critical nature of the vulnerabilities and the risk of service interruption.
- Action
- Update to the latest versions as recommended by Siemens.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch SICAM 8
Get an email when a new SICAM 8 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-05
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-547980.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-547990.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-548000.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all scored CVEs.
- Low exploitation riskCVE-2026-548010.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-54798 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54799 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54800 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54801 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0225 [1.00] [M/H] Vulnerabilities fixed in Siemens SICOREncsc-nl
- unknownMultiple vulnerabilities in Siemens products (July 10, 2026)cert-fr-avis
- highCVE-2026-54801: A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <…nvd
- mediumCVE-2026-54800: A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <…nvd
- mediumCVE-2026-54799: A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <…nvd
- mediumCVE-2026-54798: A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <…nvd
More from CISA Cybersecurity Advisories
- criticalSchneider Electric IGSS2026-07-30
- criticalOpen Source Software: Security Principles and Practices2026-07-30
- criticalMikroTik RouterOS2026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30