A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions), SICAM GridEdge Essential Intel (All versions < V2.7.3), SICAM GridEdge Essential with GDS ARM (All versions), SICAM GridEdge Essential with GDS Intel (All versions < V2.7.3). Affected software uses an improperly protected file to import SSH keys. Attackers with access to the filesystem of the host on which SICAM GridEdge runs, are able to inject a custom SSH key to that file.
2022-07-12T10:15:11.983
2024-11-21T07:09:37.340
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:P/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | siemens | sicam_gridedge_essential_arm | - | Yes |
Application | siemens | sicam_gridedge_essential_gds_arm | - | Yes |
Application | siemens | sicam_gridedge_essential_gds_intel | < 2.7.3 | Yes |
Application | siemens | sicam_gridedge_essential_intel | < 2.7.3 | Yes |