Reflected XSS Vulnerability in SICAM P850 and P855 by Siemens
CVE-2022-29876

6.1MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
20 May 2022

Summary

A vulnerability has been detected in the SICAM P850 and P855 products by Siemens, where the devices inadequately validate the input of a GET request parameter. This flaw allows attackers to manipulate parameters, which could lead to reflected XSS attacks. Consequently, malicious actors might exploit this vulnerability to execute unauthorized scripts in the context of a user's session, potentially compromising sensitive information.

Affected Version(s)

SICAM P850 All versions < V3.00

SICAM P850 All versions < V3.00

SICAM P850 All versions < V3.00

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.