Improperly Protected File Vulnerability in SICAM GridEdge Essential by Siemens
CVE-2022-34464
5.5MEDIUM
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 12 July 2022
Summary
A vulnerability exists within SICAM GridEdge Essential products, where an improperly secured file allows the importation of SSH keys. This flaw enables attackers with filesystem access to the host system to inject malicious SSH keys, potentially compromising secure connections and allowing unauthorized remote access. Users of all versions of SICAM GridEdge Essential for ARM and GDS, as well as Intel versions prior to V2.7.3, should take immediate action to mitigate the risk associated with this vulnerability.
Affected Version(s)
SICAM GridEdge Essential ARM All versions
SICAM GridEdge Essential Intel All versions < V2.7.3
SICAM GridEdge Essential with GDS ARM All versions
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved