CVE-2026-27664
CVSS 7.5 HIGH: a vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base system (All versions < V26.10.0). EPSS 0.5% (41º percentile).
Vulnerabilità ed exploit · Attacco IoT / OT
Diversi componenti dei prodotti Siemens SICAM 8 presentano vulnerabilità di denial-of-service (CVE-2026-27663, CVE-2026-27664) che causano esaurimento delle risorse quando esposti a volumi elevati di richieste. Queste vulnerabilità interessano il firmware dei dispositivi CPCI85 Central Processing/Communication, RTUM85 RTU Base e SICORE Base system, tutti utilizzati in settori critici della produzione e delle infrastrutture.
1 fonte · 2 apr
CVSS 7.5 HIGH: a vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base system (All versions < V26.10.0). EPSS 0.5% (41º percentile).
CVSS 6.5 MEDIUM: a vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base (All versions < V26.10). EPSS 0.3% (19º percentile).
CISA Advisories
Siemens SICAM 8 Products | CISA
Siemens SICAM 8 Products Summary Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - RTUM85 for CP-8010/CP-8012 - SICAM EGS…
originalePart of the PlainSec briefing for 2026-04-03
Every edition of this story: Vulnerabilità nel Firmware Siemens SICAM 8 Causano Denial of Service tramite Esaurimento delle Risorse