Vulnerability Description
A vulnerability has been identified in SICAM T (All versions < V3.0). The web based management interface of affected devices does not employ special access protection for certain internal developer views. This could allow authenticated users to access critical device information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | 7Kg8500-0Aa00-0Aa0 Firmware | < 3.00 |
| Siemens | 7Kg8500-0Aa00-0Aa0 | - |
| Siemens | 7Kg8500-0Aa00-2Aa0 Firmware | < 3.00 |
| Siemens | 7Kg8500-0Aa00-2Aa0 | - |
| Siemens | 7Kg8500-0Aa10-0Aa0 Firmware | < 3.00 |
| Siemens | 7Kg8500-0Aa10-0Aa0 | - |
| Siemens | 7Kg8500-0Aa10-2Aa0 Firmware | < 3.00 |
| Siemens | 7Kg8500-0Aa10-2Aa0 | - |
| Siemens | 7Kg8500-0Aa30-0Aa0 Firmware | < 3.00 |
| Siemens | 7Kg8500-0Aa30-0Aa0 | - |
| Siemens | 7Kg8500-0Aa30-2Aa0 Firmware | < 3.00 |
| Siemens | 7Kg8500-0Aa30-2Aa0 | - |
| Siemens | 7Kg8501-0Aa01-0Aa0 Firmware | < 3.00 |
| Siemens | 7Kg8501-0Aa01-0Aa0 | - |
| Siemens | 7Kg8501-0Aa01-2Aa0 Firmware | < 3.00 |
| Siemens | 7Kg8501-0Aa01-2Aa0 | - |
| Siemens | 7Kg8501-0Aa02-0Aa0 Firmware | < 3.00 |
| Siemens | 7Kg8501-0Aa02-0Aa0 | - |
| Siemens | 7Kg8501-0Aa02-2Aa0 Firmware | < 3.00 |
| Siemens | 7Kg8501-0Aa02-2Aa0 | - |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/html/ssa-165073.html
- https://cert-portal.siemens.com/productcert/html/ssa-471761.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-165073.pdfPatchVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-165073.pdfPatchVendor Advisory
FAQ
What is CVE-2022-29879?
CVE-2022-29879 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A vulnerability has been identified in SICAM T (All versions < V3.0). The web based management interface of affected devices does not employ special access protection for certain internal developer vi...
How severe is CVE-2022-29879?
CVE-2022-29879 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-29879?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens 7Kg8500-0Aa00-0Aa0 Firmware, Siemens 7Kg8500-0Aa00-0Aa0, Siemens 7Kg8500-0Aa00-2Aa0 Firmware, Siemens 7Kg8500-0Aa00-2Aa0, Siemens 7Kg8500-0Aa10-0Aa0 Firmware.