Impact
A weakness in the initialization of OPC UA security settings in Siemens CPCI85 Central Processing/Communication and SICORE Base system allows an attacker to gain unauthorized access and control over critical system functions. The default configuration disables all OPC UA security mechanisms, which means any OPC UA client that can connect to the device can do so without authentication or encryption. This exposes both confidentiality and integrity of protected system functions, enabling the attacker to read, write, or otherwise manipulate critical processes.
Affected Systems
Siemens CPCI85 Central Processing/Communication (all versions before V26.20) and Siemens SICORE Base system (all versions before V26.20.0) are impacted. Users of these products should verify the firmware or software version and apply available updates.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score of < 1% shows a very low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. An attacker who can reach the OPC UA endpoint can exploit the disabled security policies to read, write, or otherwise manipulate protected system functions. The lack of authentication or encryption makes this vector readily exploitable in environments where OPC UA traffic is not otherwise blocked.
OpenCVE Enrichment