Cyber Resilience
← All news
Confirmed

Siemens Siveillance Control

Our takeCISA advisory ICSA-26-265-03 reports an arbitrary file upload flaw in Siemens Siveillance Control and Control Pro (OIS 3.x.y and 4.x.y) that leads to root access on the OIS server. Siemens has released patches; update affected systems now.
Sources (1)
What this means for you — Security leader:CISA advisory ICSA-26-265-03 reports an arbitrary file upload flaw in Siemens Siveillance Control and Control Pro (OIS 3.x.y and 4.x.y) that leads to root access on the OIS server. Apply the Siemens patches immediately on your normal emergency change path.
What this means for you — Lean IT orgs:If you run Siemens Siveillance Control, this flaw lets an attacker upload files and take full control of the server. Check with your vendor or integrator right away for the update and apply it as soon as you can.
What this means for you — MSP:Siemens Siveillance Control and Pro (OIS 3/4) have a file-upload vulnerability leading to root access. Check every client running these systems and push the Siemens patches on an emergency basis.
What this means for you — Researcher:CISA ICSA-26-265-03 details an arbitrary file upload in the Open Interface Services web module of Siemens Siveillance Control and Pro (OIS 3.x.y/4.x.y) that grants root access. Patches are available.