OS Command Injection in Siemens products - CVE-2026-3014

 

OS Command Injection in Siemens products - CVE-2026-3014

Published: August 17, 2026


Vulnerability identifier: #VU143627
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-3014
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation. A remote administrator can pass specially crafted data to the application and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Siveillance Video 2023 R3
Siveillance Video 2024 R1
Siveillance Video 2025

How to mitigate CVE-2026-3014

Install updates from vendor's website.

Siveillance Video 2023 R3 - update to 23.3 HotfixRev27
Siveillance Video 2024 R1 - update to 24.1 HotfixRev16
Siveillance Video 2025 - update to 25.1 HotfixRev15

External References

Related Security Bulletins