Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43724


A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbuilt SQL server in cleartext. In combination with the by default enabled xp_cmdshell feature unauthenticated remote attackers could execute custom OS commands. At the time of assigning the CVE, the affected firmware version of the component has already been superseded by succeeding mainline versions.


Published

2022-12-13T16:15:24.327

Last Modified

2025-04-22T16:15:39.863

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-319
  • Type: Secondary
    CWE-319
  • Type: Primary
    CWE-319

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens sicam_pas\/pqs < 7.0 Yes

References