Cyber Resilience
← All news
Confirmed

Siemens Siveillance Control

Our takeCISA advisory ICSA-26-265-03 reports a file-upload flaw in Siemens Siveillance Control and Control Pro (OIS 3.x.y and 4.x.y) that leads to root access on the OIS server. Siemens has released patches; apply them immediately if you run these systems.
Sources (1)
What this means for you — Security leader:Siemens ICSA-26-265-03 details an arbitrary file upload flaw in the Open Interface Services (OIS) web module of Siveillance Control and Siveillance Control Pro (OIS 3.x.y and 4.x.y). This leads to root-level access; apply the Siemens patches immediately if you run these systems.
What this means for you — Lean IT orgs:If you run Siemens Siveillance Control or Control Pro, install the updates Siemens released for the file-upload flaw in the OIS web module. Most lean teams can do this during the next scheduled maintenance window.
What this means for you — MSP:Check every client running Siemens Siveillance Control or Control Pro (OIS 3.x.y/4.x.y) for the arbitrary file-upload vulnerability that grants root access. Deploy the Siemens patches on an emergency schedule where present.
What this means for you — Researcher:Siemens Siveillance Control and Control Pro are affected by an arbitrary file upload vulnerability in the OIS web module (ICSA-26-265-03) that results in root access. Patches are available.