CVE-2026-50093
CVSS 9 CRITICAL: a vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance… EPSS 0.2% (9º percentile).
Vulnerabilità · 16 ore fa
CISA e Siemens hanno identificato in Open Interface Services (OIS) una falla di arbitrary file upload che colpisce Siveillance Control e Siveillance Control Pro. Il difetto è classificato come CVE-2026-50093, e Siemens ha pubblicato versioni corrette per le release OIS 3.x.y e 4.x.y.
Il punto non è il caricamento in sé. Il server accetta un file che non dovrebbe accettare, e quel contenuto può finire con privilegi di root sull’host OIS. Da lì il passo è il compromesso completo dell’ambiente che ospita il servizio.
Per chi gestisce questi impianti, la notizia è che il rischio nasce dal livello host, non dal solo modulo web. Le versioni corrette sono Siveillance Control Pro V3.0 3.0.12.2173 o successive, Pro V4.0 4.0.9.2178 o successive, Control V3.0 3.0.22.2177 o successive e Control V4.0 4.0.11.2177 o successive.
CVSS 9 CRITICAL: a vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance… EPSS 0.2% (9º percentile).
1 fonte che coprono questa storia
Siemens Siveillance Control | CISA
Siemens Siveillance Control Summary A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) .
Part of the PlainSec briefing for 2026-09-22