VYPR
Unrated severityNVD Advisory· Published May 10, 2022· Updated Dec 9, 2025

CVE-2022-29872

CVE-2022-29872

Description

A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly validate parameters of POST requests. This could allow an authenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SICAM T before V3.0 fails to validate POST request parameters, allowing authenticated attackers to cause denial of service or execute arbitrary code.

Vulnerability

SICAM T versions prior to V3.0 contain a vulnerability in the handling of POST requests, where the device does not properly validate parameters [2]. This improper validation affects all versions below V3.0 and can be exploited without special conditions beyond an authenticated session [2].

Exploitation

An authenticated attacker can craft malicious POST requests to the affected device [2]. The lack of parameter validation allows the attacker to either set the device into a denial of service state or manipulate the program counter, leading to arbitrary code execution [2]. No additional network position or user interaction beyond authentication is required [2].

Impact

Successful exploitation can result in a denial of service condition or arbitrary code execution on the device [2]. An attacker gaining code execution could achieve full compromise of the SICAM T device, potentially affecting availability and integrity of the system [2].

Mitigation

Siemens has released version V3.0 for SICAM T which addresses this vulnerability [2]. Users are recommended to update to V3.0 or later [2]. Until the update is applied, restricting network access to trusted hosts (port 443/tcp) and avoiding untrusted links while logged in are advised as mitigations [2].

References
  1. SSA-471761

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.