CareCam CM2507

2026-09-15T19:23:19Z•38d6aeecd01bc5eeac99313a963c3a037c1c25892e9848574ad732e1216f24b6
CVE-2024-42384CVE-2024-42385CVE-2024-42386CVE-2024-42391CVE-2024-42392CVE-2026-58113CVE-2026-62645CVE-2026-62646CVE-2026-62647CVE-2026-62648CVE-2026-62649CVE-2026-62650CVE-2026-62652CVE-2026-62653CVE-2026-62654CVE-2026-73807CVE-2026-78225CVE-2026-80465CVE-2026-81305CVE-2026-81321CVE-2026-81855CVE-2026-81861CVE-2026-82567CVE-2026-84398CVE-2026-84400CVE-2026-85478CVE-2026-85497CVE-2026-88259CISA ICS advisoriesCareCamIP cameraOT securityRTUSCADASchneider ElectricSiemensWärtsiläaccount hijackingarbitrary code executionauthentication bypasscredential exposurecritical infrastructurecross-site scriptinghardcoded cryptographic keyindustrial control systemsmySCADA

What happened

CISA ICS advisories dated September 15, 2026 cover multiple vulnerabilities affecting CareCam CM2507 cameras, Siemens Teamcenter and Mendix SAML, Siemens Reyrolle 7SR5 protection equipment, Schneider Electric SCADAPack RTUs, mySCADA myPRO Manager, and Wärtsilä FOS-Onboard. Impacts include unauthenticated access, account hijacking, arbitrary code execution, unauthorized management functions, credential exposure, malicious updates, and operational compromise. Reported CVSS scores range from 6.1 to 9.8; organizations should apply vendor fixes or mitigations and restrict network exposure.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ics_advisories
Record identifier
38d6aeecd01bc5eeac99313a963c3a037c1c25892e9848574ad732e1216f24b6
Enrichment time
2026-09-15T19:23:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.