CVE-2022-29876

high-risk
Published 2022-05-20

A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly handle the input of a GET request parameter. The provided argument is directly reflected in the web server response. This could allow an unauthenticated attacker to perform reflected XSS attacks.

Do I need to act?

~
1.3% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.1/10 High
NETWORK / LOW complexity

Affected Products (20)

7Kg8500-0Aa00-0Aa0 Firmware
7Kg8500-0Aa00-2Aa0 Firmware
7Kg8500-0Aa10-0Aa0 Firmware
7Kg8500-0Aa10-2Aa0 Firmware
7Kg8500-0Aa30-0Aa0 Firmware
7Kg8500-0Aa30-2Aa0 Firmware
7Kg8501-0Aa01-0Aa0 Firmware
7Kg8501-0Aa01-2Aa0 Firmware
7Kg8501-0Aa02-0Aa0 Firmware
7Kg8501-0Aa02-2Aa0 Firmware
7Kg8501-0Aa11-0Aa0 Firmware
7Kg8501-0Aa11-2Aa0 Firmware
7Kg8501-0Aa12-0Aa0 Firmware
7Kg8501-0Aa12-2Aa0 Firmware
7Kg8501-0Aa31-0Aa0 Firmware
7Kg8501-0Aa31-2Aa0 Firmware
7Kg8501-0Aa32-0Aa0 Firmware
7Kg8501-0Aa32-2Aa0 Firmware
7Kg8550-0Aa00-0Aa0 Firmware
7Kg8550-0Aa00-2Aa0 Firmware

Affected Vendors

52
/ 100
high-risk
Severity 25/34 · High
Exploitability 4/34 · Minimal
Exposure 23/34 · High