Skip to content
SiemensCVE-2026-54800

Siemens CPCI85 Central Processing/Communication: insecure default

Medium6.3CVE-2026-54800 · Published Jul 9, 2026

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.

Siemens advisory

Affected versions

PackageAffectedFixed in
CPCI85 Central Processing/Communication
Product
< V26.20V26.20
SICORE Base system
Product
< V26.20.0V26.20.0
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-1188

More Siemens advisories

All Siemens
Advisory
Siemens Opcenter X: authentication bypass
Critical10.0Jul 14
Siemens SIMATIC S7-PLCSIM Advanced: denial of service
Medium6.0Jul 14
Siemens COMOS: untrusted search path
High8.5Jul 14
Siemens CPCI85 Central Processing/Communication: denial of service
High7.1Jul 9
Siemens CPCI85 Central Processing/Communication: code execution
High8.4Jul 9
Siemens CPCI85 Central Processing/Communication: authenticated attacker could...
High8.6Jul 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.