CVE-2026-50093
nicheArbitrary File Upload in Siemens Siveillance Control OIS Web Module Leads to Root Access
Siemens has disclosed an unrestricted file upload flaw (CWE-434) in the OIS web module of its Siveillance Control and Siveillance Control Pro building security management platforms. An attacker with low privileges and adjacent network access to the OIS environment can upload arbitrary files to the server. Successful exploitation can escalate to root access on the host system, resulting in a full compromise of the affected OIS environment. All affected branches are covered: Siveillance Control Pro V3.0 before V3.0.12.2173, Control Pro V4.0 before V4.0.9.2178, Control V3.0 before V3.0.22.2177, and Control V4.0 before V4.0.11.2177. There is no known public proof of concept, the issue is not in CISA's KEV catalog, and EPSS currently estimates only a 0.2% chance of exploitation in the next 30 days, indicating no known in-the-wild exploitation.
What to do: Upgrade Siveillance Control Pro V3.0 to V3.0.12.2173 or later, Control Pro V4.0 to V4.0.9.2178 or later, Control V3.0 to V3.0.22.2177 or later, and Control V4.0 to V4.0.11.2177 or later. Until patched, restrict network access to the OIS web module to trusted users and segments, since exploitation requires low-privileged access on an adjacent network. Review the OIS host for unexpected files or unusual privilege activity as a precaution.
| Siemens Siveillance Control Pro | V3.0 series: all versions < V3.0.12.2173 |
| Siemens Siveillance Control Pro | V4.0 series: all versions < V4.0.9.2178 |
| Siemens Siveillance Control | V3.0 series: all versions < V3.0.22.2177 |
| Siemens Siveillance Control | V4.0 series: all versions < V4.0.11.2177 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this vulnerability could allow an attacker to gain root access on the host system, potentially leading to a full compromise of the affected OIS environment.
- Weakness
- CWE-434
- Vector
- CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.