VulnerabilityModified
CVE-2022-29882
A vulnerability has been identified in SICAM T (All versions < V3.0).
HIGH 7.1EPSS 0.85%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not handle uploaded files correctly. An unauthenticated attacker could take advantage of this situation to store an XSS attack, which could - when a legitimate user accesses the error logs - perform arbitrary actions in the name of the user.
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- EPSS
- 0.85% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- siemens/7kg8500-0aa00-0aa0 firmware · siemens/7kg8500-0aa00-2aa0 firmware · siemens/7kg8500-0aa10-0aa0 firmware · siemens/7kg8500-0aa10-2aa0 firmware · siemens/7kg8500-0aa30-0aa0 firmware · siemens/7kg8500-0aa30-2aa0 firmware · siemens/7kg8501-0aa01-0aa0 firmware · siemens/7kg8501-0aa01-2aa0 firmware · siemens/7kg8501-0aa02-0aa0 firmware · siemens/7kg8501-0aa02-2aa0 firmware · siemens/7kg8501-0aa11-0aa0 firmware · siemens/7kg8501-0aa11-2aa0 firmware · siemens/7kg8501-0aa12-0aa0 firmware · siemens/7kg8501-0aa12-2aa0 firmware · siemens/7kg8501-0aa31-0aa0 firmware · siemens/7kg8501-0aa31-2aa0 firmware · siemens/7kg8501-0aa32-0aa0 firmware · siemens/7kg8501-0aa32-2aa0 firmware · siemens/7kg8550-0aa00-0aa0 firmware · siemens/7kg8550-0aa00-2aa0 firmware · +16 more
- Source
- productcert@siemens.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.