PT-2022-20027 · Siemens · Sicam Gridedge Essential Arm+3

Published

2022-06-14

·

Updated

2022-06-22

·

CVE-2022-30231

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SICAM GridEdge Essential ARM versions prior to V2.6.6 SICAM GridEdge Essential Intel versions prior to V2.6.6 SICAM GridEdge Essential with GDS ARM versions prior to V2.6.6 SICAM GridEdge Essential with GDS Intel versions prior to V2.6.6
Description The issue allows an authenticated user to retrieve another user's password hash upon request, as the affected software discloses password hashes of other users.
Recommendations For SICAM GridEdge Essential ARM versions prior to V2.6.6, update to version V2.6.6 or later. For SICAM GridEdge Essential Intel versions prior to V2.6.6, update to version V2.6.6 or later. For SICAM GridEdge Essential with GDS ARM versions prior to V2.6.6, update to version V2.6.6 or later. For SICAM GridEdge Essential with GDS Intel versions prior to V2.6.6, update to version V2.6.6 or later.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-30231

Affected Products

Sicam Gridedge Essential Arm
Sicam Gridedge Essential Intel
Sicam Gridedge Essential With Gds Arm
Sicam Gridedge Essential With Gds Intel