CVE-2026-54799
Awaiting Analysis Awaiting Analysis - Queue

Firmware Signature Validation Bypass in CPCI85 Central Processing

Vulnerability report for CVE-2026-54799, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-09

Last updated on: 2026-07-09

Assigner: Siemens AG

Description

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-09
Last Modified
2026-07-09
Generated
2026-07-12
AI Q&A
2026-07-09
EPSS Evaluated
2026-07-11
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
siemens cpci85 to 26.20 (exc)
siemens sicore_base_system to 26.20.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-489 The product is released with debugging code still enabled or active.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the firmware update mechanism of the CPCI85 Central Processing/Communication and SICORE Base system. Specifically, the signature validation process used during firmware updates is flawed. Because of this, an attacker could exploit the vulnerability to install malicious firmware on the affected devices.

Installing malicious firmware can lead to persistent code execution, meaning the attacker’s code remains active on the system even after reboots, resulting in a full system compromise.

Impact Analysis

The impact of this vulnerability is significant because it allows an attacker to gain persistent control over the affected system by installing malicious firmware.

  • Persistent code execution on the device
  • Complete system compromise
  • Potential disruption of device functionality and security
Detection Guidance

This vulnerability affects CPCI85 and SICORE Base system firmware versions prior to V26.20. To detect if your system is vulnerable, you should verify the firmware version of the affected devices.

Siemens recommends updating to version V26.20 or later to address this issue. Therefore, checking the firmware version on your devices is a primary detection method.

While no specific detection commands are provided in the available resources, general steps include querying the device firmware version via the device management interface or command line tools specific to the Siemens CPCI85 or SICORE systems.

Additionally, monitoring for unauthorized firmware update attempts or unusual firmware update activities on the network may help detect exploitation attempts.

It is also recommended to protect network access with firewalls and segmentation, validate updates before deployment, and ensure trained staff supervise the update process to reduce risk.

Compliance Impact

The vulnerability allows an attacker to install malicious firmware, leading to persistent code execution and system compromise. Such a compromise could potentially impact the confidentiality, integrity, and availability of systems, which are key concerns in compliance with standards like GDPR and HIPAA.

While the provided information does not explicitly mention compliance with specific regulations, the risk of unauthorized persistent code execution and system compromise could lead to violations of data protection and security requirements mandated by these standards.

Siemens recommends applying security updates, protecting network access with firewalls and segmentation, validating updates before deployment, and ensuring trained staff supervise the update process to mitigate these risks and help maintain compliance.

Mitigation Strategies

To mitigate this vulnerability, Siemens recommends updating the affected CPCI85 and SICORE Base system firmware to version V26.20 or later.

Additionally, general security measures should be followed, including protecting network access with firewalls and segmentation, validating updates before deployment, and ensuring that trained staff supervise the update process.

Operators of critical power systems are encouraged to implement resilient protection measures to minimize cyber risks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54799. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart