Remote Code Execution Vulnerability in POWER METER SICAM Q200 and P850 Series
CVE-2022-43546

9.9CRITICAL

Key Information:

Vendor
Siemens
Vendor
CVE Published:
8 November 2022

Summary

A vulnerability exists in the web interface of POWER METER SICAM Q200 and P850 series devices, stemming from improper validation of the EndTime parameter in requests sent to port 443/tcp. This oversight can be exploited by an authenticated remote attacker, leading to potential device crashes followed by automatic reboots or enabling unauthorized arbitrary code execution.

Affected Version(s)

POWER METER SICAM Q100 All versions < V2.50

POWER METER SICAM Q100 All versions < V2.50

POWER METER SICAM Q100 All versions < V2.50

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.