Unrestricted User Creation Vulnerability in SICAM GridEdge by Siemens
CVE-2022-30230
9.8CRITICAL
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 14 June 2022
Summary
A security flaw has been discovered in SICAM GridEdge that enables attackers without authentication to create new users with administrative privileges. This vulnerability affects various versions of the product, specifically all versions prior to V2.6.6 across different configurations, including ARM and Intel variants. The presence of this issue poses a significant risk as it violates access control by not requiring proper authentication for sensitive functions.
Affected Version(s)
SICAM GridEdge Essential ARM All versions < V2.6.6
SICAM GridEdge Essential Intel All versions < V2.6.6
SICAM GridEdge Essential with GDS ARM All versions < V2.6.6
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved