Description
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions.
Published: 2026-07-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A debugging interface is exposed via HTTP endpoints in Siemens CPCI85 Central Processing/Communication and SICORE Base system, allowing an authenticated attacker to crash the web process. According to the description, the flaw is also identified as CWE-489. The resulting crash reduces the availability of the web process, which in turn disrupts system services without giving the attacker further privileges or insider access.

Affected Systems

All versions of Siemens CPCI85 Central Processing/Communication prior to V26.20 and all versions of Siemens SICORE Base system prior to V26.20.0 are affected. These components are commonly used in industrial control and manufacturing automation.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity, while the EPSS score of < 1% reflects a very low but non-zero exploitation chance. The flaw is not listed in the CISA KEV catalog. The vulnerability requires authenticated access to the HTTP debugging interface; an attacker would need valid credentials and the ability to reach the endpoint, after which the process can be crashed, causing a denial of service.

Generated by OpenCVE AI on July 29, 2026 at 12:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official vendor patch provided in the Siemens advisory at https://cert-portal.siemens.com/productcert/html/ssa-229470.html.
  • Update CPCI85 and SICORE Base system to at least version V26.20 or later, which removes the vulnerable debugging interface.
  • Disable the debugging HTTP endpoints or restrict them to trusted internal networks using firewall rules.
  • Implement network segmentation so that only authorized control system devices can reach the debug endpoints.
  • Configure monitoring and alerting for repeated attempts to invoke the debugging API, which may indicate a targeted attack.

Generated by OpenCVE AI on July 29, 2026 at 12:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title HTTP Debug Interface Denial of Service in Siemens CPCI85 and SICORE Base System

Thu, 23 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title HTTP Debug Interface Denial of Service in Siemens CPCI85 and SICORE Base System

Wed, 15 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via HTTP Debugging Interface in Siemens CPCI85 and SICORE Base System

Tue, 14 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via HTTP Debugging Interface in Siemens CPCI85 and SICORE Base System

Mon, 13 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Authenticated Debugging Interface Crash Leading to Denial of Service in Siemens CPCI85 and SICORE Base Systems

Sat, 11 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Authenticated Debugging Interface Crash Leading to Denial of Service in Siemens CPCI85 and SICORE Base Systems

Fri, 10 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Authenticated Denial of Service via Debugging Interface in Siemens CPCI85 and SICORE Base System

Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Authenticated Denial of Service via Debugging Interface in Siemens CPCI85 and SICORE Base System

Thu, 09 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens cpci85 Central Processing\/communication
Siemens sicore Base System
Vendors & Products Siemens
Siemens cpci85 Central Processing\/communication
Siemens sicore Base System

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions.
Weaknesses CWE-489
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Cpci85 Central Processing\/communication Sicore Base System
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-07-09T14:54:39.999Z

Reserved: 2026-06-16T07:47:12.273Z

Link: CVE-2026-54798

cve-icon Vulnrichment

Updated: 2026-07-09T14:52:53.957Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:30:03Z

Weaknesses