ics-otregulatorNewsThe Broadside1 min read

Siemens Siveillance Control patch fixes root-access upload flaw

Four product lines across two major versions need patching; the CVSS 9 score and adjacent-network attack vector make this a prioritize-now item for critical manufacturing and communications sites.


TL;DR

Siemens released patches for CVE-2026-50093, an arbitrary file upload vulnerability in the Open Interface Services (OIS) web module used by Siveillance Control and Siveillance Control Pro. The flaw, rated CVSS 9.0, lets an authenticated attacker with adjacent-network access achieve root on the OIS server. Affected versions span both the 3.x and 4.x release lines: Control Pro 3.0 before 3.0.12.2173 and 4.0 before 4.0.9.2178; Control 3.0 before 3.0.22.2177 and 4.0 before 4.0.11.2177. Patches are available through Siemens' support portal. CISA republished the advisory on September 22, 2026.

The vulnerability sits in the OIS web module, the interface that ties Siveillance Control deployments together. CWE-434 (unrestricted upload of a file with a dangerous type) means an attacker who clears the low authentication bar can drop a payload that escalates to root. The CVSS vector (AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) confirms no user interaction is needed and the scope is changed: compromise the OIS server, and you've got a foothold in whatever that server touches.

Siemens published the advisory under SSA-254516 and reported it to CISA. The affected critical infrastructure sectors are Critical Manufacturing, Communications, and Commercial Facilities, deployments are worldwide.

What the advisory doesn't say is whether default or easily guessable credentials are common in these environments, or whether the authentication requirement is a meaningful hurdle in practice. The adjacent-network attack vector narrows the exposure surface but doesn't eliminate it: an attacker already on the operational network (through a compromised engineering workstation, a contractor laptop, or a misconfigured jump host) can reach the OIS module.

For defense contractors and manufacturers running Siveillance Control, the remediation is version-specific. Control Pro 3.0 users go to 3.0.12.2173 or later; Control Pro 4.0 to 4.0.9.2178 or later. Standard Siveillance Control 3.0 moves to 3.0.22.2177; Control 4.0 to 4.0.11.2177. Siemens provides the updates through its support portal, with links in the advisory.


Published ·Deep Fathom

Siemens Siveillance Control patch fixes root-access upload flaw — The Broadside