CVE-2022-29880 is a persistent Cross-Site Scripting (XSS) vulnerability affecting all versions of Siemens SICAM T prior to V3.0. An authenticated attacker can exploit improper input validation in the configuration interface to inject malicious scripts. This allows for arbitrary actions to be performed in the name of a logged-in user, with potential impacts on confidentiality, integrity, and availability. The vulnerability has a CVSS score of 6.5 (Medium) and is not currently known to be actively exploited, nor is there publicly available exploit code or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.00CPE matchmatch criteria | cpe:2.3:o:siemens:7kg8500-0aa00-0aa0_firmware:*:*:*:*:*:*:*:* | ||
< 3.00CPE matchmatch criteria | cpe:2.3:o:siemens:7kg8500-0aa00-2aa0_firmware:*:*:*:*:*:*:*:* | ||
< 3.00CPE matchmatch criteria | cpe:2.3:o:siemens:7kg8500-0aa10-0aa0_firmware:*:*:*:*:*:*:*:* | ||
< 3.00CPE matchmatch criteria | cpe:2.3:o:siemens:7kg8500-0aa10-2aa0_firmware:*:*:*:*:*:*:*:* | ||
< 3.00CPE matchmatch criteria | cpe:2.3:o:siemens:7kg8500-0aa30-0aa0_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.