PT-2022-20023 · Siemens · Sicam Gridedge Essential Arm+3

Published

2022-06-14

·

Updated

2022-06-24

·

CVE-2022-30228

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SICAM GridEdge Essential ARM versions prior to V2.6.6 SICAM GridEdge Essential Intel versions prior to V2.6.6 SICAM GridEdge Essential with GDS ARM versions prior to V2.6.6 SICAM GridEdge Essential with GDS Intel versions prior to V2.6.6
Description The affected software does not apply cross-origin resource sharing (CORS) restrictions for critical operations. This allows an attacker to trick a legitimate user into accessing a special resource, potentially executing a malicious request.
Recommendations For SICAM GridEdge Essential ARM versions prior to V2.6.6, update to version V2.6.6 or later. For SICAM GridEdge Essential Intel versions prior to V2.6.6, update to version V2.6.6 or later. For SICAM GridEdge Essential with GDS ARM versions prior to V2.6.6, update to version V2.6.6 or later. For SICAM GridEdge Essential with GDS Intel versions prior to V2.6.6, update to version V2.6.6 or later. As a temporary workaround, consider implementing additional security measures to restrict access to critical operations until the update is applied.

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-30228

Affected Products

Sicam Gridedge Essential Arm
Sicam Gridedge Essential Intel
Sicam Gridedge Essential With Gds Arm
Sicam Gridedge Essential With Gds Intel