Parameter Validation Flaw in SICAM P850 and SICAM P855 Devices by Siemens
CVE-2022-29872

8.7HIGH

Key Information:

Vendor

Siemens

Status
Vendor
CVE Published:
20 May 2022

What is CVE-2022-29872?

A vulnerability has been identified within Siemens SICAM P850 and SICAM P855 devices, where improper validation of POST request parameters may be exploited. An authenticated attacker could potentially set the device into a denial of service state, or manipulate the program counter to execute arbitrary code on the device. This flaw emphasizes the importance of robust parameter validation to safeguard against malicious manipulations.

Affected Version(s)

SICAM T 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.