Flooding Attack Vulnerability in SICAM MMU, SGU, and T Products by Siemens
CVE-2020-10037

7.5HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
14 July 2020

Summary

A vulnerability exists in Siemens' SICAM product suite that can be exploited through a flooding attack on the web server. This attack may allow unauthorized users to gain read access to the device's memory, which could potentially lead to the exposure of sensitive and confidential information stored within the device. The affected products include all versions of SICAM SGU, all SICAM MMU versions prior to V2.05, and all SICAM T versions prior to V2.18.

Affected Version(s)

SICAM MMU All versions < V2.05

SICAM SGU All versions

SICAM T All versions < V2.18

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.