Skip to main content
Disclosures

Siemens · SICAM SIAPP SDK

Command Injection via Shell Command Construction

7.4high
SecMateSECMATE-2026-0009
VendorSiemens
ProductSICAM SIAPP SDK
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
Reported
Jan 3, 2026
Acknowledged
Feb 18, 2026
Published
Mar 10, 2026
Summary

The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially resulting in command injection and full system compromise.

Read the technical analysis

What's hidden in yours?

Find out