VYPR
Unrated severityNVD Advisory· Published May 10, 2022· Updated Dec 9, 2025

CVE-2022-29874

CVE-2022-29874

Description

A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not encrypt web traffic with clients but communicate in cleartext via HTTP. This could allow an unauthenticated attacker to capture the traffic and interfere with the functionality of the device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SICAM T devices before V3.0 transmit web traffic in cleartext via HTTP, allowing an unauthenticated attacker to capture and interfere with device functionality.

Vulnerability

A cleartext transmission vulnerability exists in the web interface of SICAM T devices running versions prior to V3.0. The affected devices do not encrypt web traffic with clients but communicate in cleartext via HTTP. This issue is identified as CVE-2022-29874 and affects all versions of SICAM T before V3.0 [2].

Exploitation

An unauthenticated attacker with network access to the affected device can capture HTTP traffic using standard packet sniffing tools. No authentication or user interaction is required for the attacker to intercept the cleartext communications. The attacker can also actively interfere with device functionality by injecting or manipulating HTTP requests [1][2].

Impact

Successful exploitation allows an attacker to capture sensitive information transmitted between the client and device, including credentials and configuration data. Additionally, the attacker can interfere with the functionality of the device, potentially leading to denial of service, unauthorized access, or manipulation of device operations [2].

Mitigation

Siemens has released version V3.00 to address this vulnerability. Affected users should update to SICAM T V3.00 or later. The update can be obtained from the Siemens Industry Online Support portal. As a workaround, restrict network access to port 80/tcp and 443/tcp to trusted IP addresses only [1][2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.