PT-2022-5904 · Siemens · Sicam P850+2
Published
2022-11-08
·
Updated
2024-01-09
·
CVE-2022-43546
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
POWER METER SICAM Q100 versions prior to V2.50
SICAM P850 versions prior to V3.10
SICAM P855 versions prior to V3.10
Description
The issue is related to errors in processing input data, specifically with the EndType parameter in the web interface of the affected devices. This could allow a remote attacker to crash the device, which would then automatically reboot, or execute arbitrary code on the device. The affected devices do not properly validate the
EndTime parameter in requests to the web interface on port 443/tcp.Recommendations
For POWER METER SICAM Q100 versions prior to V2.50, update to version V2.50 or later.
For SICAM P850 versions prior to V3.10, update to version V3.10 or later.
For SICAM P855 versions prior to V3.10, update to version V3.10 or later.
As a temporary workaround, consider restricting access to the web interface on port 443/tcp to minimize the risk of exploitation. Avoid using the
EndTime parameter in requests to the web interface until the issue is resolved.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Power Meter Sicam Q100
Sicam P850
Sicam P855