Malicious firmware installation possible via critical vulnerabilities in Siemens CPCI85 processing units
Critical vulnerabilities in Siemens CPCI85 central processing units could allow attackers to install malicious firmware or bypass security controls. Affected devices include those used in SICAM A8000 and SICAM EGS systems. Update to V26.20 or later immediately to mitigate these risks.
Summary
Multiple vulnerabilities have been identified in the CPCI85 Central Processing/Communication unit used within Siemens SICAM products. These flaws impact the signature validation process during firmware updates, the handling of administrative credentials via a web API, and the default configuration of OPC UA security mechanisms.
The vulnerabilities affect several hardware configurations, including the CP-8031/CP-8050 devices and the SICORE base system used in various SICAM A8000 and S8000 packages. Exploitation could lead to persistent code execution through malicious firmware or unauthorized elevation of privileges.
Technical details
The vulnerabilities target different layers of the CPCI85 and SICORE systems:
- Firmware Integrity: CVE-2026-54799 involves a flaw in the firmware update mechanism's signature validation process. An attacker could exploit this to install malicious firmware, resulting in persistent code execution and full system compromise.
- Privilege Escalation: CVE-2026-54801 stems from insufficient validation of authentication credentials when processing administrative account modifications through the web API. This allows an authenticated attacker to bypass security controls and gain elevated privileges.
- Denial of Service: CVE-2026-54798 affects a debugging interface accessible via HTTP endpoints. An authenticated attacker can crash the web process, causing a denial of service condition.
- Security Configuration: CVE-2026-54800 identifies that the default configuration disables all OPC UA security mechanisms, which could allow unauthorized access to critical system functions.
Affected products and fixed versions
The following products are affected by these vulnerabilities. Siemens has released updated firmware packages to address them.
| Product | Affected Component | Fixed Version |
|---|---|---|
| SICAM A8000 (CP-8031/CP-8050) | CPCI85 Firmware | V26.20 or later |
| SICAM EGS | CPCI85 Firmware | V26.20 or later |
| SICAM A8000 (CP-8010/CP-8012) | SICORE Base System | V26.20.0 or later |
| SICAM S8000 | SICORE Base System | V26.20.0 or later |
Defender guidance
Siemens recommends updating all affected devices using the provided tooling and documented procedures. Before applying any update, validate the firmware in a test environment and supervise the process with trained staff.
To reduce the attack surface, implement these network-level controls:
- Protect network access using firewalls, segmentation, and VPNs.
- Configure environments according to Siemens operational guidelines to ensure devices run in protected IT environments.
- For operators of critical power systems (such as TSOs or DSOs), verify that multi-level redundant secondary protection schemes are active to maintain grid reliability during a cyber incident.
