CVE-2022-27480
12.04.2022, 09:15
A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do not require an user to be authenticated to access certain files. This could allow unauthenticated attackers to download these files.
Vendor | Product | Version |
---|---|---|
siemens | sicam_a8000_cp-8031_firmware | 𝑥 < 4.80 |
siemens | sicam_a8000_cp-8050_firmware | 𝑥 < 4.80 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-862 - Missing AuthorizationThe software does not perform an authorization check when an actor attempts to access a resource or perform an action.
- CWE-425 - Direct Request ('Forced Browsing')The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
References