PT-2022-2724 · Siemens · Siemens Sicam P850+1
Published
2022-04-28
·
Updated
2022-06-02
·
CVE-2022-29878
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Siemens SICAM P850 versions prior to V3.00
Siemens SICAM P855 versions prior to V3.00
Description
The issue is related to the bypass of authentication procedures using a capture-replay attack on intercepted parameters. This could allow a remote attacker to gain access to the device's management interface. Affected devices use a limited range for challenges sent during unencrypted challenge-response communication, allowing an unauthenticated attacker to capture a valid challenge-response pair and reuse it to access the management interface.
Recommendations
For Siemens SICAM P850 versions prior to V3.00, update to version V3.00 or later.
For Siemens SICAM P855 versions prior to V3.00, update to version V3.00 or later.
As a temporary workaround, consider restricting access to the management interface until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siemens Sicam P850
Siemens Sicam P855