← Knowledge Center
Advisory CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801

Siemens SICAM 8 flaws include unverified password change and insecure defaults

CISA has published an ICS advisory for Siemens SICAM 8 products (including CPCI85 and SICORE base systems used in energy and critical manufacturing). The flaws (CVE-2026-54798 through CVE-2026-54801) span active debug code exposed via HTTP endpoints, initialization of a resource with an insecure default, and — notably from an identity perspective — an unverified password change weakness. These could enable authenticated attackers to disrupt operation or manipulate credential controls.

While the primary impact described is denial of service, the unverified password change and insecure default initialization issues touch directly on access-control integrity in OT environments. Siemens has released fixed versions (26.20 and later) and recommends updating.

What to take away: even in industrial systems, weaknesses in password-change verification and default credential handling can undermine identity assurance; organizations running SICAM 8 should patch and audit access controls promptly.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.