PT-2022-20023 · Siemens · Sicam Gridedge Essential Arm+3
Published
2022-06-14
·
Updated
2022-06-24
·
CVE-2022-30228
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SICAM GridEdge Essential ARM versions prior to V2.6.6
SICAM GridEdge Essential Intel versions prior to V2.6.6
SICAM GridEdge Essential with GDS ARM versions prior to V2.6.6
SICAM GridEdge Essential with GDS Intel versions prior to V2.6.6
Description
The affected software does not apply cross-origin resource sharing (CORS) restrictions for critical operations. This allows an attacker to trick a legitimate user into accessing a special resource, potentially executing a malicious request.
Recommendations
For SICAM GridEdge Essential ARM versions prior to V2.6.6, update to version V2.6.6 or later.
For SICAM GridEdge Essential Intel versions prior to V2.6.6, update to version V2.6.6 or later.
For SICAM GridEdge Essential with GDS ARM versions prior to V2.6.6, update to version V2.6.6 or later.
For SICAM GridEdge Essential with GDS Intel versions prior to V2.6.6, update to version V2.6.6 or later.
As a temporary workaround, consider implementing additional security measures to restrict access to critical operations until the update is applied.
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sicam Gridedge Essential Arm
Sicam Gridedge Essential Intel
Sicam Gridedge Essential With Gds Arm
Sicam Gridedge Essential With Gds Intel