WORLDTECH NEWS Global technology intelligence.Contact
โ† Back to WORLDTECH
Cybersecurity

Siemens Siveillance Control

Two analysts silhouetted in front of monitors in a security operations centerAI illustration
WORLDTECH illustration ยท AI-generated (Canva)

What happened

Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions. View CSAF Summary A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) .

This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. It is advised to follow recommended security practices in order to run the devices in a protected IT environment.

Legal Notice and Terms of Use This product is provided subject to this Notification ( https://www.cisa.gov/notification ) and this Privacy & Use policy ( https://www.cisa.gov/privacy-policy ). Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.

Key facts

  • Siemens has โ€” released: patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions

Sources & evidence