CVE Database
/

CVE-2022-43724

Back to search

CVE-2022-43724

Published: Dec 13, 2022

Modified: Apr 22, 2025

PUBLISHED

Description

A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbuilt SQL server in cleartext. In combination with the by default enabled xp_cmdshell feature unauthenticated remote attackers could execute custom OS commands. At the time of assigning the CVE, the affected firmware version of the component has already been superseded by succeeding mainline versions.

VendorProductVersions

Siemens

SICAM PAS/PQS

affected
All versions < V7.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now