Flooding Attack Vulnerability in SICAM MMU, SGU, and T Products by Siemens
CVE-2020-10037
7.5HIGH
Summary
A vulnerability exists in Siemens' SICAM product suite that can be exploited through a flooding attack on the web server. This attack may allow unauthorized users to gain read access to the device's memory, which could potentially lead to the exposure of sensitive and confidential information stored within the device. The affected products include all versions of SICAM SGU, all SICAM MMU versions prior to V2.05, and all SICAM T versions prior to V2.18.
Affected Version(s)
SICAM MMU All versions < V2.05
SICAM SGU All versions
SICAM T All versions < V2.18
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved