Kwetsbaarheden worden geladen…
Kwetsbaarheden worden geladen…
CVE-2026-54800
The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.
Dit record: live koppeling — laatst opgehaald: 25 juli 2026 om 01:35.
Leverancier
Siemens
Product
CPCI85 Central Processing/Communication
Gepubliceerd
25 juli 2026
Laatst gewijzigd
25 juli 2026
The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack vector
NETWORK
Privileges required
NONE
User interaction
NONE
Vertrouwelijkheid
Geen
Integriteit
Geen
Beschikbaarheid
Geen
Beperkte impact op beschikbaarheid; risico ligt vooral bij vertrouwelijkheid of integriteit van procesdata.
Beoordeeld als relevant voor de energiesector op basis van: Vermeld in een officiële CISA ICS Advisory, wat directe relevantie voor industriële besturingssystemen bevestigt. Productbeschrijving komt overeen met de categorie "opc-server", een typisch OT/ICS-componenttype. Leverancier "Siemens" is een bekende leverancier van apparatuur voor de energiesector. Beschrijving noemt industrieel protocol: opc-ua.
Update to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/
IACS Radar-duiding
Automatisch geclassificeerd als industrieel relevant op basis van CISA/NVD-signalen (zie redenen).
Geclassificeerd door IACS Radar-analysepijplijn (geautomatiseerd) op 25 juli 2026.
IACS Radar-duiding
IEC 62443-mapping
Automatische IACS Radar-duiding op basis van de gerapporteerde CWE-zwakteclassificatie; geen officiële certificeringsuitspraak.