Description
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.
Published: 2026-07-09
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A weakness in the initialization of OPC UA security settings in Siemens CPCI85 Central Processing/Communication and SICORE Base system allows an attacker to gain unauthorized access and control over critical system functions. The default configuration disables all OPC UA security mechanisms, which means any OPC UA client that can connect to the device can do so without authentication or encryption. This exposes both confidentiality and integrity of protected system functions, enabling the attacker to read, write, or otherwise manipulate critical processes.

Affected Systems

Siemens CPCI85 Central Processing/Communication (all versions before V26.20) and Siemens SICORE Base system (all versions before V26.20.0) are impacted. Users of these products should verify the firmware or software version and apply available updates.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. The EPSS score of < 1% shows a very low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. An attacker who can reach the OPC UA endpoint can exploit the disabled security policies to read, write, or otherwise manipulate protected system functions. The lack of authentication or encryption makes this vector readily exploitable in environments where OPC UA traffic is not otherwise blocked.

Generated by OpenCVE AI on July 26, 2026 at 15:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware upgrade to SIEMENS CPCI85 or SICORE Base system (V26.20 or newer).
  • If an upgrade is not immediately possible, re‑enable all OPC UA security mechanisms in the system configuration to enforce authentication and encryption.
  • Restrict OPC UA traffic to trusted networks or block untrusted connections using firewalls or network segmentation.

Generated by OpenCVE AI on July 26, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title OPC UA Security Disabled in Siemens CPCI85 and SICORE Base Systems

Wed, 22 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Disabled OPC UA Security Allows Unauthorized Access to Siemens CPCI85 and SICORE Base System

Thu, 16 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Disabled OPC UA Security Allows Unauthorized Access to Siemens CPCI85 and SICORE Base System

Wed, 15 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via Disabled OPC UA Security in Siemens CPCI85 and SICORE Systems

Tue, 14 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via Disabled OPC UA Security in Siemens CPCI85 and SICORE Systems

Mon, 13 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Unsecured OPC UA Default Configuration in Siemens CPCI85 and SICORE Systems

Sun, 12 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unsecured OPC UA Default Configuration in Siemens CPCI85 and SICORE Systems

Sat, 11 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title OPC UA Security Disabled Enables Unauthorized Access in Siemens CPCI85 and SICORE

Fri, 10 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title OPC UA Security Disabled Enables Unauthorized Access in Siemens CPCI85 and SICORE

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens cpci85 Central Processing\/communication
Siemens sicore Base System
Vendors & Products Siemens
Siemens cpci85 Central Processing\/communication
Siemens sicore Base System

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.
Weaknesses CWE-1188
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Cpci85 Central Processing\/communication Sicore Base System
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-07-09T14:45:11.451Z

Reserved: 2026-06-16T07:47:12.274Z

Link: CVE-2026-54800

cve-icon Vulnrichment

Updated: 2026-07-09T14:45:05.272Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T15:30:04Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default