Siemens patches SICAM 8 firmware signature bypass
The hard case is CVE-2026-54799: malicious firmware can outlast the maintenance window that critical infrastructure patching usually gets.
TL;DR
The Cybersecurity and Infrastructure Security Agency warned that Siemens SICAM 8 CPCI85 and SICORE versions before V26.20/V26.20.0 carry four flaws: HTTP-exposed debug code, firmware signature bypass, insecure defaults and weak web API credential checks. Siemens says to update affected CP-8031/CP-8050, CP-8010/CP-8012, SICAM EGS and S8000 packages. Energy, critical manufacturing and defense industrial base operators, plus Cybersecurity Maturity Model Certification Third-Party Assessment Organizations, should focus on CVE-2026-54799 because malicious firmware creates persistence in environments that usually patch slowly.
The Cybersecurity and Infrastructure Security Agency's Siemens SICAM 8 advisory covers CPCI85 Central Processing/Communication versions before V26.20 and SICORE Base system versions before V26.20.0, across SICAM A8000, SICAM EGS and SICAM S8000 deployments, including the CP-8031/CP-8050 and CP-8010/CP-8012 packages. Siemens has fixes in V26.20 and V26.20.0. Those are clean version targets for environments where firmware updates usually move through planned outages and formal change control.
The flaw list is mixed. CVE-2026-54798 exposes active debug code through HTTP endpoints and can let an authenticated attacker crash the web process. CVE-2026-54800 ships a default configuration that disables Open Platform Communications Unified Architecture security mechanisms. CVE-2026-54801 covers insufficient credential validation for administrative account changes through the web application programming interface and carries the advisory's high Common Vulnerability Scoring System score, 7.2.
CVE-2026-54799 is the maintenance-window problem. CISA says the firmware update mechanism does not properly validate signatures, allowing malicious firmware installation that can lead to persistent code execution and system compromise. In a segmented operational technology network, persistence changes the cleanup problem. Restoring service no longer closes the file if the trusted update path was the thing that failed.
For defense industrial base operators, Cybersecurity Maturity Model Certification Third-Party Assessment Organizations and operational technology assessors, Monday's work is dull and necessary: find CPCI85 and SICORE versions in CP-8031/CP-8050, CP-8010/CP-8012, SICAM EGS and S8000 deployments, test the Siemens updates under documented procedures, and preserve the evidence. The advisory names the fixed versions; it does not supply an operator deployment timeline. That gap matters most in plants that patch only inside narrow outage windows.
Published ·Deep Fathom