Unauthorized Data Modification in SICAM GridEdge Essential by Siemens
CVE-2022-30229

5.3MEDIUM

Summary

A serious security flaw exists in SICAM GridEdge Essential software that permits unauthorized users to perform privileged actions without authentication. This vulnerability allows attackers to alter user data, including sensitive credentials, provided they know the user ID. Affected versions include all versions prior to V2.6.6 for various configurations of the product. This weakness can significantly compromise the integrity and confidentiality of the affected systems, making it crucial for users to update to the latest version to mitigate potential risks.

Affected Version(s)

SICAM GridEdge Essential ARM All versions < V2.6.6

SICAM GridEdge Essential Intel All versions < V2.6.6

SICAM GridEdge Essential with GDS ARM All versions < V2.6.6

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.