The vendor explicitly identifies these products as affected by this CVE.
- CPCI85 Central Processing/Communication < V26.20
- SICORE Base system < V26.20.0
- Summary
- The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.
- Remediation
- Update to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/
