Security/ siemens · ics-security · surveillance · vulnerability

Siemens patches critical flaw in surveillance control software

A file upload bug in Siemens Siveillance Control lets an attacker on the network gain root access to the surveillance server, and Siemens has issued a patch.

Siemens' video surveillance platform had a hole big enough to hand attackers the keys to the server.

CISA and Siemens disclosed CVE-2026-50093, a critical flaw (CVSS 9.0) in the Open Interface Services (OIS) web module used by Siveillance Control and Siveillance Control Pro. The bug lets an attacker upload arbitrary files to the server, which can escalate to full root access on the host. It hits OIS versions 3.x and 4.x across both product lines - specifically Control Pro builds before 3.0.12.2173 and 4.0.9.2178, and Control builds before 3.0.22.2177 and 4.0.11.2177. Siemens has shipped patched versions for all four affected lines and wants customers on them now.

Siveillance runs physical security systems - the cameras and access control tied to critical manufacturing, communications, and commercial facilities worldwide. A root-level compromise of the server managing that hardware doesn't just leak footage; it can hand an attacker control over doors, badges, and camera feeds. That is a bigger prize than the average software bug, which is why CISA rated this a 9 out of 10 even though exploitation requires network-adjacent access rather than a wide-open internet path.

An attacker still needs a foothold on the local network first, so this isn't drive-by exploitable from anywhere - but plenty of "isolated" ICS segments end up bridged to corporate networks anyway, which is usually how that caveat stops mattering.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →