ZeroHour

CVE-2022-29881

CVSS 4.0
6.9 medium
EPSS
1%p63
Published
()
Modified
Description

A vulnerability has been identified in SICAM T (All versions < V3.0). The web based management interface of affected devices does not employ special access protection for certain internal developer views. This could allow unauthenticated users to extract internal configuration details.

Vendors
siemens
Products
7kg8500-0aa00-0aa0 firmware, 7kg8500-0aa00-2aa0 firmware, 7kg8500-0aa10-0aa0 firmware, 7kg8500-0aa10-2aa0 firmware, 7kg8500-0aa30-0aa0 firmware, 7kg8500-0aa30-2aa0 firmware, 7kg8501-0aa01-0aa0 firmware, 7kg8501-0aa01-2aa0 firmware, 7kg8501-0aa02-0aa0 firmware, 7kg8501-0aa02-2aa0 firmware, 7kg8501-0aa11-0aa0 firmware, 7kg8501-0aa11-2aa0 firmware
Weakness
CWE-306
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.