VYPR
Unrated severityNVD Advisory· Published May 10, 2022· Updated Dec 9, 2025

CVE-2022-29873

CVE-2022-29873

Description

A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly validate parameters of certain GET and POST requests. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated attacker can cause a denial of service or execute arbitrary code by sending specially crafted GET/POST requests to SICAM T devices before version 3.0.

Vulnerability

An improper parameter validation vulnerability exists in the web interface of SICAM T devices on all versions prior to V3.0 [1][2]. The affected devices do not properly validate parameters of certain GET and POST requests, which can be exploited without authentication [1].

Exploitation

An unauthenticated attacker with network access to the affected device can send specially crafted GET or POST requests to the web interface [2]. No prior authentication or user interaction is required. The attacker can manipulate parameters to trigger the vulnerability, potentially setting the device to a denial of service state or controlling the program counter to execute arbitrary code [1].

Impact

Successful exploitation can result in denial of service (compromising availability) or arbitrary code execution with full control over the device, potentially allowing the attacker to compromise confidentiality, integrity, and availability of the device and its data [1][2]. The CVSS v3.1 base score for this vulnerability is 9.9, indicating critical severity [2].

Mitigation

Siemens has released version V3.00 for SICAM T as the fixed version [2]. Users must update to V3.00 or later to remediate the vulnerability. As workarounds, Siemens recommends restricting access to port 443/tcp to trusted IP addresses only and avoiding accessing links from untrusted sources while logged in to SICAM T [2]. The vulnerability is not yet listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.