CVE-2022-29873
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly validate parameters of certain GET and POST requests. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 2.97%
- CWE
- CWE-141
- Published
- 2022-05-10
- Last modified
- 2026-03-13
Affected products
- Siemens SICAM T
Weakness type
Related vulnerabilities
- CVE-2026-66323 — Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2026-19594 — Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege Escalation
- CVE-2026-20200 — Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability
- CVE-2026-56813 — Cookie attribute injection in Plug.Conn.Cookies.encode/2
- CVE-2025-20338 — A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker...
- CVE-2025-31329 — Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
- CVE-2024-0840 — Grandstream UCM Series IP PBX HTTP Parameter Injection
- CVE-2022-41665 — A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.10),...