Impact
A debugging interface is exposed via HTTP endpoints in Siemens CPCI85 Central Processing/Communication and SICORE Base system, allowing an authenticated attacker to crash the web process. According to the description, the flaw is also identified as CWE-489. The resulting crash reduces the availability of the web process, which in turn disrupts system services without giving the attacker further privileges or insider access.
Affected Systems
All versions of Siemens CPCI85 Central Processing/Communication prior to V26.20 and all versions of Siemens SICORE Base system prior to V26.20.0 are affected. These components are commonly used in industrial control and manufacturing automation.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity, while the EPSS score of < 1% reflects a very low but non-zero exploitation chance. The flaw is not listed in the CISA KEV catalog. The vulnerability requires authenticated access to the HTTP debugging interface; an attacker would need valid credentials and the ability to reach the endpoint, after which the process can be crashed, causing a denial of service.
OpenCVE Enrichment