Description
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.
Published: 2026-07-09
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the firmware update mechanism of the Siemens CPCI85 Central Processing/Communication and SICORE Base system allows an attacker to bypass the cryptographic signature validation, permitting installation of malicious firmware. Installing such firmware results in persistent code execution, giving the attacker full control over the affected device once it boots and continues to operate thereafter.

Affected Systems

All Siemens CPCI85 Central Processing/Communication devices and all Siemens SICORE Base system devices that run firmware versions earlier than V26.20 (or V26.20.0 for SICORE) are vulnerable. The issue applies to every model variant documented within those product families.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity vulnerability, and the EPSS of less than 1% shows a very low but non-zero probability of exploitation. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker must initiate a firmware update, which typically requires network access or valid update credentials. Once the update is performed, the malicious firmware is installed and executed, providing persistent control over the device.

Generated by OpenCVE AI on July 29, 2026 at 12:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to Siemens V26.20 or later to eliminate the signature validation flaw.
  • If a public update is not yet available, restrict firmware update capability to a secure, internally controlled network segment and enforce strict authentication to prevent unauthorized update uploads.
  • Continuously monitor firmware update logs and verify system integrity after any update activity to detect potential tampering and ensure that the device remains uncompromised.

Generated by OpenCVE AI on July 29, 2026 at 12:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Malicious Firmware Bypass in Siemens CPCI85 and SICORE Base System

Fri, 24 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Malicious Firmware Bypass in Siemens CPCI85 and SICORE Base System

Tue, 21 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Malicious Firmware Installation via Bypassed Signature Validation in Siemens CPCI85 and SICORE Devices

Thu, 16 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Malicious Firmware Installation via Bypassed Signature Validation in Siemens CPCI85 and SICORE Devices

Wed, 15 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Firmware Update Signature Validation Failure Leading to Persistent Code Execution

Sun, 12 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Firmware Update Signature Validation Failure Leading to Persistent Code Execution

Fri, 10 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Firmware Signature Validation Exploit in Siemens CPCI85 and SICORE Base Systems

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Firmware Signature Validation Exploit in Siemens CPCI85 and SICORE Base Systems

Thu, 09 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens cpci85 Central Processing\/communication
Siemens sicore Base System
Vendors & Products Siemens
Siemens cpci85 Central Processing\/communication
Siemens sicore Base System

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.
Weaknesses CWE-489
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Cpci85 Central Processing\/communication Sicore Base System
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-07-09T14:46:38.615Z

Reserved: 2026-06-16T07:47:12.273Z

Link: CVE-2026-54799

cve-icon Vulnrichment

Updated: 2026-07-09T14:46:35.722Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:30:03Z

Weaknesses