VendorsSiemenssicam_gridedge_essentialany version
Vulnerabilities

Siemens Sicam Gridedge Essential any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-30230
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to create a new user with administrative permissions.
Published 2022-06-14 · Modified
9.8EPSS 0.011
CVE-2022-30228
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected software does not apply cross-origin resource sharing (CORS) restrictions for critical operations. In case an attacker tricks a legitimate user into accessing a special resource a malicious request could be executed.
Published 2022-06-14 · Modified
8.8EPSS 0.004
CVE-2022-30229
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to change data of a user, such as credentials, in case that user's id is known.
Published 2022-06-14 · Modified
8.6EPSS 0.007
CVE-2022-30231
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application discloses password hashes of other users upon request. This could allow an authenticated user to retrieve another user's password hash.
Published 2022-06-14 · Modified
6.9EPSS 0.006