PT-2022-27018 · Unknown · Sicam Pas/Pqs

Published

2022-12-13

·

Updated

2023-10-17

·

CVE-2022-43724

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SICAM PAS/PQS versions prior to V7.0
Description A security issue has been identified where the affected software transmits database credentials for the inbuilt SQL server in cleartext. This, combined with the default enabled xp cmdshell feature, allows unauthenticated remote attackers to execute custom OS commands.
Recommendations For versions prior to V7.0, update to version V7.0 or later to resolve the issue. As a temporary workaround, consider disabling the xp cmdshell feature to minimize the risk of exploitation. Restrict access to the SQL server to prevent unauthenticated remote attacks.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-43724

Affected Products

Sicam Pas/Pqs