Authentication Bypass in SICAM MMU, SGU, and T by Siemens
CVE-2020-10045

8.8HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
14 July 2020

Summary

A vulnerability exists in the SICAM MMU, SGU, and T products from Siemens due to an error in the challenge-response mechanism. An attacker could exploit this flaw to replay authenticated traffic, potentially gaining unauthorized access to restricted areas of the related web application. This issue underscores the importance of robust authentication mechanisms to ensure the integrity of access controls.

Affected Version(s)

SICAM MMU All versions < V2.05

SICAM SGU All versions

SICAM T All versions < V2.18

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.