Skip to content
SiemensCVE-2026-54799

Siemens CPCI85 Central Processing/Communication: code execution

High8.4CVE-2026-54799 · Published Jul 9, 2026

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.

Siemens advisory

Affected versions

PackageAffectedFixed in
CPCI85 Central Processing/Communication
Product
< V26.20V26.20
SICORE Base system
Product
< V26.20.0V26.20.0
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-489

More Siemens advisories

All Siemens
Advisory
Siemens Opcenter X: authentication bypass
Critical10.0Jul 14
Siemens SIMATIC S7-PLCSIM Advanced: denial of service
Medium6.0Jul 14
Siemens COMOS: untrusted search path
High8.5Jul 14
Siemens CPCI85 Central Processing/Communication: denial of service
High7.1Jul 9
Siemens CPCI85 Central Processing/Communication: insecure default
Medium6.3Jul 9
Siemens CPCI85 Central Processing/Communication: authenticated attacker could...
High8.6Jul 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.