CVE-2022-34464 Information

Description

A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions) SICAM GridEdge Essential Intel (All versions < V2.7.3) SICAM GridEdge Essential with GDS ARM (All versions) SICAM GridEdge Essential with GDS Intel (All versions < V2.7.3). Affected software uses an improperly protected file to import SSH keys. Attackers with access to the filesystem of the host on which SICAM GridEdge runs are able to inject a custom SSH key to that file.

Reference

https://cert-portal.siemens.com/productcert/pdf/ssa-225578.pdf

Share on: