CVE-2022-29874 Information

Description

A vulnerability has been identified in SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P850 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00) SICAM P855 (All versions < V3.00). Affected devices do not encrypt web traffic with clients but communicate in cleartext via HTTP. This could allow an unauthenticated attacker to capture the traffic and interfere with the functionality of the device.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Reference

https://cert-portal.siemens.com/productcert/pdf/ssa-165073.pdf

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

7.5

Share on: