CVE-2026-27664

7.5

Siemens · CPCI85 Central Processing/Communication, SICORE Base system

An out-of-bounds write vulnerability in Siemens CPCI85 and SICORE Base system allows unauthenticated attackers to cause a denial-of-service via crafted XML inputs.

Executive summary

An unauthenticated remote denial-of-service vulnerability in Siemens CPCI85 and SICORE Base system components poses a significant risk to industrial system availability.

Vulnerability

The affected software components contain an out-of-bounds write vulnerability triggered during the parsing of specially crafted XML inputs. An unauthenticated attacker can exploit this flaw by sending a malicious request, leading to a service crash and a subsequent denial-of-service condition.

Business impact

Successful exploitation of this vulnerability results in the disruption of critical processing and communication services. Given that these components are integral to industrial operations, a denial-of-service condition could lead to unplanned downtime, operational delays, and potential safety implications for the affected infrastructure. With a CVSS score of 7.5, this issue represents a high-severity risk that requires immediate attention to ensure system continuity.

Remediation

Immediate Action: Update Siemens CPCI85 Central Processing/Communication to version V26.10 or later and SICORE Base system to version V26.10.0 or later as specified in the vendor security advisory.

Proactive Monitoring: Monitor system logs for frequent service restarts or unusual XML-related error messages that may indicate an attempt to trigger the crash condition.

Compensating Controls: Deploy network-level traffic inspection or a Web Application Firewall (WAF) configured to inspect and block malformed XML payloads directed at the vulnerable services.

Exploitation status

Public Exploit Available: exploit_available (false)

Analyst recommendation

This vulnerability presents a clear risk to the availability of critical industrial systems due to the lack of required authentication. Organizations operating the affected Siemens software should prioritize the application of the vendor-supplied updates to prevent potential service disruptions. Please review the official Siemens security portal for specific deployment instructions to ensure a secure transition to the patched versions.

More Siemens CVEs

Sources