CVE-2022-27480
Summary
| CVE | CVE-2022-27480 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-12 09:15:00 UTC |
| Updated | 2023-07-18 13:54:00 UTC |
| Description | A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do not require an user to be authenticated to access certain files. This could allow unauthenticated attackers to download these files. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Siemens A8000 CP-8050/CP-8031 SICAM WEB Missing File Download / Missing Authentication ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| N/A |
CONFIRM |
cert-portal.siemens.com |
|
| Full Disclosure: SEC Consult SA-20220413 :: Missing Authentication at File Download & Denial of Service in Siemens A8000 PLC |
FULLDISC |
seclists.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590872 Siemens SICAM A8000 Vulnerability (ICSA-22-104-10) (SSA-316850)