Man-in-the-Middle Vulnerability in SICAM Products by Siemens
CVE-2020-10039

8.1HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
14 July 2020

Summary

A vulnerability exists in Siemens SICAM products that may allow an attacker positioned within a privileged network to perform a Man-in-the-Middle attack. This could lead to unauthorized read and write access to sensitive data being transmitted between the legitimate user and the web server. Users of SICAM MMU versions below 2.05, SICAM SGU, and SICAM T versions below 2.18 are particularly affected, emphasizing the need for immediate upgrades to mitigate this serious risk.

Affected Version(s)

SICAM MMU All versions < V2.05

SICAM SGU All versions

SICAM T All versions < V2.18

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.