Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-29878


A vulnerability has been identified in SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00), SICAM P855 (All versions < V3.00). Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker could capture a valid challenge-response pair generated by a legitimate user, and request the webpage repeatedly to wait for the same challenge to reappear for which the correct response is known. This could allow the attacker to access the management interface of the device.


Published

2022-05-20T13:15:16.177

Last Modified

2024-11-21T06:59:53.087

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-294
  • Type: Primary
    CWE-294

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens 7kg8500-0aa00-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8500-0aa00-0aa0 - No
Operating System siemens 7kg8500-0aa00-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8500-0aa00-2aa0 - No
Operating System siemens 7kg8500-0aa10-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8500-0aa10-0aa0 - No
Operating System siemens 7kg8500-0aa10-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8500-0aa10-2aa0 - No
Operating System siemens 7kg8500-0aa30-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8500-0aa30-0aa0 - No
Operating System siemens 7kg8500-0aa30-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8500-0aa30-2aa0 - No
Operating System siemens 7kg8501-0aa01-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8501-0aa01-0aa0 - No
Operating System siemens 7kg8501-0aa01-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8501-0aa01-2aa0 - No
Operating System siemens 7kg8501-0aa02-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8501-0aa02-0aa0 - No
Operating System siemens 7kg8501-0aa02-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8501-0aa02-2aa0 - No
Operating System siemens 7kg8501-0aa11-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8501-0aa11-0aa0 - No
Operating System siemens 7kg8501-0aa11-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8501-0aa11-2aa0 - No
Operating System siemens 7kg8501-0aa12-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8501-0aa12-0aa0 - No
Operating System siemens 7kg8501-0aa12-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8501-0aa12-2aa0 - No
Operating System siemens 7kg8501-0aa31-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8501-0aa31-0aa0 - No
Operating System siemens 7kg8501-0aa31-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8501-0aa31-2aa0 - No
Operating System siemens 7kg8501-0aa32-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8501-0aa32-0aa0 - No
Operating System siemens 7kg8501-0aa32-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8501-0aa32-2aa0 - No
Operating System siemens 7kg8550-0aa00-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8550-0aa00-0aa0 - No
Operating System siemens 7kg8550-0aa00-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8550-0aa00-2aa0 - No
Operating System siemens 7kg8550-0aa10-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8550-0aa10-0aa0 - No
Operating System siemens 7kg8550-0aa10-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8550-0aa10-2aa0 - No
Operating System siemens 7kg8550-0aa30-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8550-0aa30-0aa0 - No
Operating System siemens 7kg8550-0aa30-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8550-0aa30-2aa0 - No
Operating System siemens 7kg8551-0aa01-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8551-0aa01-0aa0 - No
Operating System siemens 7kg8551-0aa01-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8551-0aa01-2aa0 - No
Operating System siemens 7kg8551-0aa02-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8551-0aa02-0aa0 - No
Operating System siemens 7kg8551-0aa02-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8551-0aa02-2aa0 - No
Operating System siemens 7kg8551-0aa11-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8551-0aa11-0aa0 - No
Operating System siemens 7kg8551-0aa11-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8551-0aa11-2aa0 - No
Operating System siemens 7kg8551-0aa12-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8551-0aa12-0aa0 - No
Operating System siemens 7kg8551-0aa12-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8551-0aa12-2aa0 - No
Operating System siemens 7kg8551-0aa31-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8551-0aa31-0aa0 - No
Operating System siemens 7kg8551-0aa31-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8551-0aa31-2aa0 - No
Operating System siemens 7kg8551-0aa32-0aa0_firmware < 3.00 Yes
Hardware siemens 7kg8551-0aa32-0aa0 - No
Operating System siemens 7kg8551-0aa32-2aa0_firmware < 3.00 Yes
Hardware siemens 7kg8551-0aa32-2aa0 - No

References