CVE-2026-3014
Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Siveillance Video are affected: Siveillance Video V2023 R3 vers:intdot/Siveillance Video V2024 R1 vers:intdot/Siveillance Video V2025 vers:intdot/ CVSS Vendor Equipment Vulnerabilities v3 9.1 Siemens Siemens Siveillance Video Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors: Critical Manufacturing, Communications, Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
EPSS 0.78% · 53.5th percentile
Risk Scores
Timeline
- Jul 14, 2026 EPSS Score
- Jul 14, 2026 CVE Published
- Jul 15, 2026 Coalition ESS Score
- Aug 7, 2026 EPSS Score
- Aug 11, 2026 CVE Updated
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-09 advisory
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-09.json advisory
- https://www.cve.org/CVERecord?id=CVE-2026-3014 technical
- https://support.industry.siemens.com/cs/ww/en/view/109827783/ vendor
- https://support.industry.siemens.com/cs/ww/en/view/109976123/ vendor
- https://support.industry.siemens.com/cs/ww/en/view/109988670/ vendor
- https://cwe.mitre.org/data/definitions/78.html technical
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H technical