Back to search
CVE-2022-27480
Published: Apr 12, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do not require an user to be authenticated to access certain files. This could allow unauthenticated attackers to download these files.
| Vendor | Product | Versions |
|---|---|---|
Siemens | SICAM A8000 CP-8031 | affected All versions < V4.80 |
Siemens | SICAM A8000 CP-8050 | affected All versions < V4.80 |
Weaknesses (CWE)
References
https://cert-portal.siemens.com/productcert/pdf/ssa-316850.pdf
x_refsource_MISC
20220414 SEC Consult SA-20220413 :: Missing Authentication at File Download & Denial of Service in Siemens A8000 PLC
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now