PT-2022-20027 · Siemens · Sicam Gridedge Essential Arm+3
Published
2022-06-14
·
Updated
2022-06-22
·
CVE-2022-30231
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
SICAM GridEdge Essential ARM versions prior to V2.6.6
SICAM GridEdge Essential Intel versions prior to V2.6.6
SICAM GridEdge Essential with GDS ARM versions prior to V2.6.6
SICAM GridEdge Essential with GDS Intel versions prior to V2.6.6
Description
The issue allows an authenticated user to retrieve another user's password hash upon request, as the affected software discloses password hashes of other users.
Recommendations
For SICAM GridEdge Essential ARM versions prior to V2.6.6, update to version V2.6.6 or later.
For SICAM GridEdge Essential Intel versions prior to V2.6.6, update to version V2.6.6 or later.
For SICAM GridEdge Essential with GDS ARM versions prior to V2.6.6, update to version V2.6.6 or later.
For SICAM GridEdge Essential with GDS Intel versions prior to V2.6.6, update to version V2.6.6 or later.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sicam Gridedge Essential Arm
Sicam Gridedge Essential Intel
Sicam Gridedge Essential With Gds Arm
Sicam Gridedge Essential With Gds Intel