2026-07-10NOTABLESiemens patches a firmware-signing bypass and an insecure OPC UA default in SICAM 8 grid-protection controllers, plan the out-of-band OT update
Siemens SICAM 8 HTTP-reachable debug interface → authenticated DoS
cve · CVE-2026-54798
Coverage
1
first 2026-07-10 → last 2026-07-10
Latest activity
2026-07-10
Siemens patches a firmware-signing bypass and an insecure OPC UA default in SICAM 8 grid-protection…
Peak priority
notable
1 notable
Targets
energy
sectors: energy · regions: europe
Sources cited
2
2 hosts
Action items (3)
Do-now tasks recorded on the entries about CVE-2026-54798, newest first. Check the date before acting on an older one.
- Plan an out-of-band firmware update to CPCI85 ≥ V26.20 / SICORE ≥ V26.20.0 across SICAM A8000/EGS/S8000 estates; validate in a test environment and supervise the update per Siemens' documented procedure before rolling to production grid devices.2026-07-10CVE-2026-54799 +3
- Audit SICAM 8 OPC UA configuration, the shipped default disables OPC UA security (CVE-2026-54800); enable it and confirm the OPC UA interface is not network-reachable from untrusted zones.2026-07-10CVE-2026-54799 +3
- Restrict network access to SICAM device HTTP/web-API and OPC UA interfaces via segmentation, firewalls and VPN; treat the debug HTTP endpoint (CVE-2026-54798) as attack surface and confirm resilient redundant protection is in place per grid-design guidance.2026-07-10CVE-2026-54799 +3
Defender insights
What each entry about CVE-2026-54798 tells a defender to do, newest first.
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (4 across 5 tactics)
4 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- PersistenceAccount Manipulation
- Privilege EscalationAccount Manipulation
- Defense ImpairmentModify System Image
- Lateral MovementExploitation of Remote Services
- ImpactEndpoint Denial of Service
Persistence TA0003
T1098Account Manipulation×1
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
Evidence: 2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass · ATT&CK page ↗
Privilege Escalation TA0004
T1098Account Manipulation×1
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
Evidence: 2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass · ATT&CK page ↗
Defense Impairment TA0112
T1601Modify System Image×1
Adversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves. On such devices, the operating systems are typically monolithic and most of the device functionality and capabilities are contained within a single file.
Evidence: 2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass · ATT&CK page ↗
Lateral Movement TA0008
T1210Exploitation of Remote Services×1
Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. A common goal for post-compromise exploitation of remote services is for lateral movement to enable access to a remote system.
Evidence: 2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass · ATT&CK page ↗
Impact TA0040
T1499Endpoint Denial of Service×1
Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users. Endpoint DoS can be performed by exhausting the system resources those services are hosted on or exploiting the system to cause a persistent crash condition. Example services include websites, email services, DNS, and web-based applications. Adversaries have been observed conducting DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.
Evidence: 2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass · ATT&CK page ↗
Entries about Siemens SICAM 8 HTTP-reachable debug interface → authenticated DoS (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Siemens SICAM 8 firmware-update signature-validation bypass → persistent malicious firmware×1
- Siemens SICAM 8 ships with OPC UA security disabled by default×1
- Siemens SICAM 8 web-API admin-account credential-validation bypass → privilege escalation×1
- Siemens SICAM A8000 CP-8010/CP-8012 (SICORE firmware)×1
- Siemens SICAM A8000 CP-8031/CP-8050 (CPCI85 firmware)×1
- Siemens SICAM EGS (CPCI85 firmware)×1
- Siemens SICAM S8000 (SICORE firmware)×1
Where this entity is cited
Source distribution
- cert-portal.siemens.com1 (50%)
- cert.ssi.gouv.fr1 (50%)