Full Report
A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions.
Analysis Summary
# Vulnerability: Arbitrary File Upload in Siemens Siveillance OIS Web Module
## CVE Details
- **CVE ID:** CVE-2026-50093
- **CVSS Score:** 9.0 (Critical) - CVSS v3.1 / 8.9 (High) - CVSS v4.0
- **CWE:** CWE-434 (Unrestricted Upload of File with Dangerous Type)
## Affected Systems
- **Products:**
- Siveillance Control (formerly Siveillance Viewpoint)
- Siveillance Control Pro
- **Versions:**
- Siveillance Control V3.0: All versions prior to V3.0.22.2177
- Siveillance Control V4.0: All versions prior to V4.0.11.2177
- Siveillance Control Pro V3.0: All versions prior to V3.0.12.2173
- Siveillance Control Pro V4.0: All versions prior to V4.0.9.2178
- **Configurations:** The flaw resides within the Open Interface Services (OIS) web module integrated into these products.
## Vulnerability Description
The Open Interface Services (OIS) web module fails to properly restrict or validate files uploaded to the server. An authenticated attacker can exploit this lack of restriction to upload arbitrary, potentially malicious files (such as web shells). Because the OIS module processes these uploads with elevated privileges, successful exploitation allows the attacker to achieve unauthorized root-level access on the host operating system.
## Exploitation
- **Status:** Not currently reported as exploited in the wild; no public PoC provided in advisory.
- **Complexity:** Low (Successful exploitation requires minimal technical effort once authenticated).
- **Attack Vector:** Adjacent (Attacker must be on the same shared subnet or local network).
- **Privileges Required:** Low (Attacker needs basic user access to the module).
## Impact
- **Confidentiality:** High (Full access to all data on the OIS server).
- **Integrity:** High (Ability to modify system files and application data).
- **Availability:** High (Potential for complete system shutdown or denial of service).
## Remediation
### Patches
Siemens recommends updating to the following versions or later:
- **Siveillance Control V3.0:** Update to V3.0.22.2177
- **Siveillance Control V4.0:** Update to V4.0.11.2177
- **Siveillance Control Pro V3.0:** Update to V3.0.12.2173
- **Siveillance Control Pro V4.0:** Update to V4.0.9.2178
### Workarounds
- **Network Segmentation:** Protect network access to affected products with firewalls and VLANs to ensure they are only accessible from trusted parts of the network.
- **Access Control:** Strictly limit user access to the OIS web module to the absolute minimum necessary personnel.
## Detection
- **Indicators of Compromise:**
- Presence of unexpected files in web-accessible directories.
- Unusual process activity originating from the OIS web service user.
- Unauthorized configuration changes or creation of new administrative users.
- **Detection methods and tools:**
- Monitor web server logs for suspicious file upload requests (POST requests to upload endpoints).
- File Integrity Monitoring (FIM) on the OIS server directories.
## References
- **Siemens Security Advisory:** SSA-254516
- **Vendor Advisory Link:** hxxps[://]cert-portal[.]siemens[.]com/productcert/html/ssa-254516[.]html
- **Support Links:**
- hxxps[://]support[.]industry[.]siemens[.]com/cs/ww/en/view/110004859/
- hxxps[://]support[.]industry[.]siemens[.]com/cs/ww/en/view/110004860/