PT-2022-5906 · Siemens · Sicam P850+2

Published

2022-11-08

·

Updated

2024-01-09

·

CVE-2022-43439

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions POWER METER SICAM Q100 versions prior to V2.50 SICAM P850 versions prior to V3.10 SICAM P855 versions prior to V3.10
Description The issue is related to errors in processing input data, specifically with the Language parameter in the web interface of the affected devices. This could allow a remote attacker to crash the device, leading to an automatic reboot, or execute arbitrary code on the device. The affected devices do not properly validate the Language-parameter in requests to the web interface on port 443/tcp.
Recommendations For POWER METER SICAM Q100 versions prior to V2.50, update to version V2.50 or later. For SICAM P850 versions prior to V3.10, update to version V3.10 or later. For SICAM P855 versions prior to V3.10, update to version V3.10 or later. As a temporary workaround, consider restricting access to the web interface on port 443/tcp to minimize the risk of exploitation. Avoid using the Language parameter in requests to the web interface until the issue is resolved.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-07322
CVE-2022-43439

Affected Products

Power Meter Sicam Q100
Sicam P850
Sicam P855