PT-2022-2724 · Siemens · Siemens Sicam P850+1

Published

2022-04-28

·

Updated

2022-06-02

·

CVE-2022-29878

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Siemens SICAM P850 versions prior to V3.00 Siemens SICAM P855 versions prior to V3.00
Description The issue is related to the bypass of authentication procedures using a capture-replay attack on intercepted parameters. This could allow a remote attacker to gain access to the device's management interface. Affected devices use a limited range for challenges sent during unencrypted challenge-response communication, allowing an unauthenticated attacker to capture a valid challenge-response pair and reuse it to access the management interface.
Recommendations For Siemens SICAM P850 versions prior to V3.00, update to version V3.00 or later. For Siemens SICAM P855 versions prior to V3.00, update to version V3.00 or later. As a temporary workaround, consider restricting access to the management interface until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03228
CVE-2022-29878

Affected Products

Siemens Sicam P850
Siemens Sicam P855