Command Injection Rated Critical
CISA published ICS advisory ICSA-26-225-09 on August 13, 2026, describing a critical vulnerability in Siemens Siveillance Video, a video management platform deployed worldwide across the critical manufacturing, communications and commercial facilities sectors. Tracked as CVE-2026-3014 and rated CWE-78 (OS Command Injection), the flaw affects Siveillance Video V2023 R3 versions before 23.3.27, V2024 R1 versions before 24.1.16, and V2025 versions before 25.1.15, with a CVSS v3 base score of 9.1.
According to the advisory, a user with edit permissions on the Management Server can exploit the flaw to execute arbitrary code in the context of the Management Server service, which could allow an attacker to take control of connected video management infrastructure.
Updates Available for All Affected Branches
Siemens has released fixed versions for each affected release branch: V23.3 HotfixRev27 or later, V24.1 HotfixRev16 or later, and the V25.1.15 update for the 2025 branch. CISA and Siemens recommend that operators update to the corrected versions as soon as practical and, in line with general ICS hardening guidance, restrict Management Server edit permissions to trusted administrators and segment video management infrastructure from untrusted networks.

Leave a Reply