CVE-2022-29874
published 2022-05-20CVE-2022-29874: A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not encrypt web traffic with clients but communicate in cleartext via…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.69%
48.5th percentile
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not encrypt web traffic with clients but communicate in cleartext via HTTP. This could allow an unauthenticated attacker to capture the traffic and interfere with the functionality of the device.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | 7kg8500-0aa00-0aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8500-0aa00-2aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8500-0aa10-0aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8500-0aa10-2aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8500-0aa30-0aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8500-0aa30-2aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8501-0aa01-0aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8501-0aa01-2aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8501-0aa02-0aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8501-0aa02-2aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8501-0aa11-0aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8501-0aa11-2aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8501-0aa12-0aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8501-0aa12-2aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8501-0aa31-0aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8501-0aa31-2aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8501-0aa32-0aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8501-0aa32-2aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8550-0aa00-0aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8550-0aa00-2aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8550-0aa10-0aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8550-0aa10-2aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8550-0aa30-0aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8550-0aa30-2aa0_firmware | < 3.00 | 3.00 |
| siemens | 7kg8551-0aa01-0aa0_firmware | < 3.00 | 3.00 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6vgf-xpr3-4724: A vulnerability has been identified in SICAM P850 (All versions < V3
ghsa_unreviewed·2022-05-21
CVE-2022-29874 [HIGH] CWE-319 GHSA-6vgf-xpr3-4724: A vulnerability has been identified in SICAM P850 (All versions < V3
A vulnerability has been identified in SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions <
CISA ICS
Siemens SICAM P850 and SICAM P855
cisa_ics·2022-05-12
Siemens SICAM P850 and SICAM P855
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SICAM P850 and SICAM P855
Last RevisedMay 12, 2022
Alert CodeICSA-22-132-07
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Siemens SICAM P850 and SICAM P855
- Vulnerabilities: Improper Neutralization of Parameter/Argument Delimiters, Cleartext Transmission of Sensitive Information, Cross-site Scripting, Missing Authentication for Critical Function, Authentication Bypass by Capture-replay, Improper Authentication
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-20
Published