Update affected Siveillance Video Management Server software to the latest hotfix versions: V23.3 HotfixRev27 or later, V24.1 HotfixRev16 or later, or V25.1 HotfixRev15 or later. Restrict network access to Management Server interfaces. Apply principle of least privilege for user permissions. Follow Siemens and CISA recommended security practices for industrial control system devices.
Quick answers
What is CVE-2026-3014?
Update affected Siveillance Video Management Server software to the latest hotfix versions: V23.3 HotfixRev27 or later, V24.1 HotfixRev16 or later, or V25.1 HotfixRev15 or later. Restrict network access to Management Server interfaces. Apply principle of least privilege for user permissions. Follow Siemens and CISA recommended security practices for industrial control system devices.
How severe is CVE-2026-3014?
critical, CVSS 9.1
Is CVE-2026-3014 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-3014 be mitigated?
Update affected Siveillance Video Management Server software to the latest hotfix versions: V23.3 HotfixRev27 or later, V24.1 HotfixRev16 or later, or V25.1 HotfixRev15 or later. Restrict network access to Management Server interfaces. Apply principle of least privilege for user permissions. Follow Siemens and CISA recommended security practices for industrial control system devices.
CVSS
9.1
Vendor
Siemens
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Siveillance Video V2023 R3, Siveillance Video V2024 R1, Siveillance Video V2025
Mitigation
Update affected Siveillance Video Management Server software to the latest hotfix versions: V23.3 HotfixRev27 or later, V24.1 HotfixRev16 or later, or V25.1 HotfixRev15 or later. Restrict network access to Management Server interfaces. Apply principle of least privilege for user permissions. Follow Siemens and CISA recommended security practices for industrial control system devices.
Siemens Siveillance Video Management Servers contain a critical vulnerability tracked as CVE-2026-3014. The flaw is an improper neutralization of special elements used in an OS command (OS command injection) that could allow a remote attacker with edit permissions to the Management Server to execute arbitrary code in the context of the Management Server Service. The vulnerability affects Siveillance Video V2023 R3 versions earlier than 23.3.27, V2024 R1 versions earlier than 24.1.16, and Siveillance Video V2025 versions earlier than 25.1.15. Siemens has released corresponding hotfix updates to address the issue. No public exploitation has been reported at the time of advisory publication.