PT-2022-5904 · Siemens · Sicam P850+2

Published

2022-11-08

·

Updated

2024-01-09

·

CVE-2022-43546

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions POWER METER SICAM Q100 versions prior to V2.50 SICAM P850 versions prior to V3.10 SICAM P855 versions prior to V3.10
Description The issue is related to errors in processing input data, specifically with the EndType parameter in the web interface of the affected devices. This could allow a remote attacker to crash the device, which would then automatically reboot, or execute arbitrary code on the device. The affected devices do not properly validate the EndTime parameter in requests to the web interface on port 443/tcp.
Recommendations For POWER METER SICAM Q100 versions prior to V2.50, update to version V2.50 or later. For SICAM P850 versions prior to V3.10, update to version V3.10 or later. For SICAM P855 versions prior to V3.10, update to version V3.10 or later. As a temporary workaround, consider restricting access to the web interface on port 443/tcp to minimize the risk of exploitation. Avoid using the EndTime parameter in requests to the web interface until the issue is resolved.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-07320
CVE-2022-43546

Affected Products

Power Meter Sicam Q100
Sicam P850
Sicam P855