Parameter Validation Flaw in SICAM P850 and SICAM P855 Devices by Siemens
CVE-2022-29872

8.8HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
20 May 2022

Summary

A vulnerability has been identified within Siemens SICAM P850 and SICAM P855 devices, where improper validation of POST request parameters may be exploited. An authenticated attacker could potentially set the device into a denial of service state, or manipulate the program counter to execute arbitrary code on the device. This flaw emphasizes the importance of robust parameter validation to safeguard against malicious manipulations.

Affected Version(s)

SICAM P850 All versions < V3.00

SICAM P850 All versions < V3.00

SICAM P850 All versions < V3.00

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.