Impact
Affected Siemens CPCI85 Central Processing/Communication and SICORE Base systems contain insufficient authentication validation for administrative account modifications processed through the web API. The CWE-620 weakness allows an attacker with existing valid credentials to bypass security checks and elevate their privileges, potentially granting full administrative control over the device.
Affected Systems
All versions of Siemens CPCI85 Central Processing/Communication and SICORE Base systems prior to V26.20 are affected. The vulnerability exists in any release before the specified version threshold.
Risk and Exploitability
The CVSS score of 8.6 classifies this flaw as high severity. The EPSS score is less than 1%, indicating a very low but non‑zero risk of exploitation in practice. The vulnerability is not listed in the CISA KEV catalog. An attacker who has already authenticated can exploit the web API to modify administrative accounts and gain elevated privileges. Based on the description, it is inferred that the web API is reachable over the network, enabling remote exploitation when network access is granted.
OpenCVE Enrichment