Siemens SICAM 8 Firmware Flaws Cause Denial of Service via Resource Exhaustion

Multiple Siemens SICAM 8 products used in critical manufacturing have denial-of-service vulnerabilities (CVE-2026-27663, CVE-2026-27664). These flaws cause resource exhaustion when devices receive high volumes of requests, forcing a reset or reboot to restore operation. Affected components include CPCI85 Central Processing/Communication, RTUM85 RTU Base, and SICORE Base system firmware versions before 26.10 or 26.10.0. Siemens has released fixed firmware versions (26.10 or later) across multiple SICAM 8 product lines. Operators must verify no vulnerable versions remain and update accordingly. Because the issue spans several device types, remediation requires coordinated firmware updates rather than a single patch. Network-level rate limiting can help mitigate attack impact until updates are applied.

Part of the PlainSec briefing for 2026-04-03

Sources