CVE-2026-50093
9.0Siemens · Siveillance Control / Siveillance Control Pro
A vulnerability in the OIS web module of Siemens Siveillance Control and Control Pro allows an authenticated attacker to upload arbitrary files, potentially resulting in root-level system compromise.
Executive summary
A critical arbitrary file upload vulnerability in Siemens Siveillance Control products allows attackers with low privileges to achieve full root access on the host system.
Vulnerability
This is an unrestricted file upload vulnerability (CWE-434) within the OIS web module. While the vulnerability requires low privileges (PR:L) and an adjacent network connection (AV:A), it permits an authenticated user to upload malicious files that can lead to remote code execution with root privileges.
Business impact
The potential for root-level compromise of the Siveillance Control environment poses a severe risk to operational security and system integrity. Given the CVSS score of 9.0, this vulnerability is categorized as critical, as it allows for total control over the affected server, which may facilitate lateral movement or the disruption of critical safety and security monitoring services.
Remediation
Immediate Action: Update all instances of Siemens Siveillance Control and Siveillance Control Pro to the versions specified in the enrichment data (V3.0.12.2173, V4.0.9.2178, V3.0.22.2177, or V4.0.11.2177 respectively).
Proactive Monitoring: Review web access logs for suspicious file uploads to the OIS module and monitor system integrity for any unauthorized modifications to root-level binaries or configuration files.
Compensating Controls: Implement strict Web Application Firewall (WAF) rules to filter and block unauthorized file uploads to the OIS web module until the patches are successfully deployed.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for full system compromise, organizations should prioritize the immediate application of the vendor-supplied updates. Failure to patch these systems leaves critical infrastructure components exposed to potential unauthorized administrative control.
More Siemens CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section