{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/siveillance-control-pro-v3.0--3.0.12.2173-v4.0--4.0.9.2178/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9,"id":"CVE-2026-50093"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Siveillance Control Pro (V3.0 \u003c 3.0.12.2173, V4.0 \u003c 4.0.9.2178)","Siveillance Control (V3.0 \u003c 3.0.22.2177, V4.0 \u003c 4.0.11.2177)"],"_cs_severities":["critical"],"_cs_tags":["ics","scada","cve-2026-50093","arbitrary-file-upload"],"_cs_type":"advisory","_cs_vendors":["Siemens"],"content_html":"\u003cp\u003eSiemens has disclosed a critical security vulnerability, CVE-2026-50093, affecting the Open Interface Services (OIS) web module within Siveillance Control and Siveillance Control Pro software. This vulnerability, categorized as CWE-434 (Unrestricted Upload of File with Dangerous Type), stems from improper validation of file uploads handled by the web interface.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this flaw by uploading arbitrary files, such as malicious scripts or web shells, to the OIS server. Successful exploitation grants the attacker root-level access to the underlying host system, leading to a complete compromise of the Siveillance environment. Given that this system is used for critical infrastructure management, including communications and manufacturing, the impact is severe. Siemens has released specific patches for versions 3.x and 4.x and strongly advises organizations to isolate these control systems from internet-facing networks to prevent unauthorized access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-50093 results in full administrative (root) control over the affected Siveillance Control server. This enables attackers to pivot within industrial networks, exfiltrate sensitive process data, or disrupt operational technology services. This vulnerability impacts critical infrastructure across the manufacturing, communications, and commercial sectors globally.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch affected systems immediately by upgrading to the following versions:\u003c/li\u003e\n\u003cli\u003eSiveillance Control Pro V3.0 to V3.0.12.2173 or later.\u003c/li\u003e\n\u003cli\u003eSiveillance Control Pro V4.0 to V4.0.9.2178 or later.\u003c/li\u003e\n\u003cli\u003eSiveillance Control V3.0 to V3.0.22.2177 or later.\u003c/li\u003e\n\u003cli\u003eSiveillance Control V4.0 to V4.0.11.2177 or later.\u003c/li\u003e\n\u003cli\u003eIsolate Siveillance Control servers from the public internet using firewalls and access control lists to prevent external reachability.\u003c/li\u003e\n\u003cli\u003eRestrict access to the OIS web interface to authorized management subnets only.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation between the control system network and business IT networks to mitigate potential lateral movement following a compromise.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T16:47:18Z","date_published":"2026-09-22T16:47:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-siemens-siveillance/","summary":"A critical file upload vulnerability (CVE-2026-50093) in the Siemens Siveillance Control OIS web module allows unauthenticated or low-privileged remote attackers to achieve root-level code execution.","title":"Arbitrary File Upload Vulnerability in Siemens Siveillance Control","url":"https://feed.craftedsignal.io/briefs/2026-09-siemens-siveillance/"}],"language":"en","title":"CraftedSignal Threat Feed - Siveillance Control Pro (V3.0 \u003c 3.0.12.2173, V4.0 \u003c 4.0.9.2178)","version":"https://jsonfeed.org/version/1.1"}