VORANT. Threat Intelligence Sign in Get the full feed

Siemens Siveillance OIS Arbitrary File Upload Flaw

routine vulnerability manufacturingtelecommunicationsinfrastructure

An arbitrary file upload vulnerability in Siemens Siveillance Control's OIS web module can allow root-level access to the server; patches available.

CISA republished a Siemens ProductCERT advisory (SSA-254516) describing an arbitrary file upload vulnerability (CVE-2026-50093, CWE-434) in the Open Interface Services (OIS) web module used by Siveillance Control and Siveillance Control Pro. An attacker able to reach the OIS web interface could upload arbitrary files to the server, potentially achieving root-level access and full compromise of the OIS environment. No CVSS score, exploitation status, or in-the-wild activity is mentioned in the advisory text; this appears to be a vendor-reported vulnerability rather than one currently under active exploitation.

Affected versions include Siveillance Control Pro V3.0 prior to 3.0.12.2173, V4.0 prior to 4.0.9.2178, and Siveillance Control V3.0 prior to 3.0.22.2177 and V4.0 prior to 4.0.11.2177. Siemens has released patched versions and update links for each affected product line. Defenders running Siveillance Control/Control Pro should update to the fixed OIS versions immediately, and in the interim ensure the OIS web module and broader control system network are not exposed to the internet, are segmented behind firewalls, and are only reachable via secure remote access methods such as VPNs, consistent with standard ICS network hardening practices.

The affected products are used in critical manufacturing, communications, and commercial facilities sectors worldwide, with Siemens headquartered in Germany. This is a standard CISA ICS advisory (verbatim republication) with no indication of a coordinated attack campaign, threat actor, or malware associated with this vulnerability at the time of publication.

Mentioned in this report

Vulnerabilities CVE-2026-50093

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-03

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free