PT-2022-3225 · Siemens · Sicam P850+1

Published

2022-04-28

·

Updated

2022-06-02

·

CVE-2022-29880

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SICAM P850 versions prior to V3.00 SICAM P855 versions prior to V3.00
Description The issue is related to the configuration interface of the affected devices, which do not properly validate input. This could allow an authenticated attacker to perform arbitrary actions in the name of a logged user who accesses the affected views by placing persistent XSS attacks.
Recommendations For SICAM P850 versions prior to V3.00, update to version V3.00 or later. For SICAM P855 versions prior to V3.00, update to version V3.00 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03927
CVE-2022-29880

Affected Products

Sicam P850
Sicam P855