CVE-2026-25571: Medium severity Siemens SICAM SIAPP SDK vulnerability
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK client component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25571?
CVE-2026-25571 has been classified as a high severity vulnerability due to the potential for stack overflow attacks.
How do I fix CVE-2026-25571?
To mitigate CVE-2026-25571, upgrade the SICAM SIAPP SDK to version 2.1.7 or higher, which includes the necessary fixes.
What types of attacks can CVE-2026-25571 enable?
CVE-2026-25571 can enable attackers to execute stack overflow attacks that may disrupt the operation of the SICAM SIAPP SDK client component.
Which versions of SICAM SIAPP SDK are affected by CVE-2026-25571?
All versions of the SICAM SIAPP SDK prior to version 2.1.7 are affected by CVE-2026-25571.
What components of SICAM SIAPP SDK does CVE-2026-25571 impact?
CVE-2026-25571 specifically impacts the client component of the SICAM SIAPP SDK by failing to enforce maximum length checks.