CVE-2022-27480
Siemens A8000 CP-8050/CP-8031 SICAM WEB Missing File Download / Missing Authentication
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do not require an user to be authenticated to access certain files. This could allow unauthenticated attackers to download these files.
Se ha identificado una vulnerabilidad en SICAM A8000 CP-8031 (todas las versiones anteriores a V4.80), SICAM A8000 CP-8050 (todas las versiones anteriores a V4.80). Los dispositivos afectados no requieren que el usuario sea autenticado para acceder a determinados archivos. Esto podrĂa permitir a atacantes no autenticados descargar estos archivos
Siemens A8000 CP-8050/CP-8031 SICAM WEB suffers from denial of service and a missing authentication vulnerability that allows for file download.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-21 CVE Reserved
- 2022-04-12 CVE Published
- 2024-08-03 CVE Updated
- 2024-12-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-425: Direct Request ('Forced Browsing')
- CWE-862: Missing Authorization
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/166743/Siemens-A8000-CP-8050-CP-8031-SICAM-WEB-Missing-File-Download-Missing-Authentication.html | Third Party Advisory | |
http://seclists.org/fulldisclosure/2022/Apr/20 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-316850.pdf | 2023-07-18 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Sicam A8000 Cp-8031 Firmware Search vendor "Siemens" for product "Sicam A8000 Cp-8031 Firmware" | < 4.80 Search vendor "Siemens" for product "Sicam A8000 Cp-8031 Firmware" and version " < 4.80" | - |
Affected
| in | Siemens Search vendor "Siemens" | Sicam A8000 Cp-8031 Search vendor "Siemens" for product "Sicam A8000 Cp-8031" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Sicam A8000 Cp-8050 Firmware Search vendor "Siemens" for product "Sicam A8000 Cp-8050 Firmware" | < 4.80 Search vendor "Siemens" for product "Sicam A8000 Cp-8050 Firmware" and version " < 4.80" | - |
Affected
| in | Siemens Search vendor "Siemens" | Sicam A8000 Cp-8050 Search vendor "Siemens" for product "Sicam A8000 Cp-8050" | - | - |
Safe
|