Skip to main content
Disclosures

Siemens · SICAM SIAPP SDK

Command Injection via Shell Command Construction

7.4high
SecMateSECMATE-2026-0009
VendorSiemens
ProductSICAM SIAPP SDK
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
Reported
Jan 3, 2026
Acknowledged
Feb 18, 2026
Published
Mar 10, 2026
Summary

The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially resulting in command injection and full system compromise.

What's hidden in yours?

Find out