VYPR
Unrated severityNVD Advisory· Published May 10, 2022· Updated Dec 9, 2025

CVE-2022-29878

CVE-2022-29878

Description

A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker could capture a valid challenge-response pair generated by a legitimate user, and request the webpage repeatedly to wait for the same challenge to reappear for which the correct response is known. This could allow the attacker to access the management interface of the device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SICAM T devices before V3.0 use a limited challenge space in unencrypted challenge-response authentication, enabling replay attacks that can lead to unauthorized management access.

Vulnerability

SICAM T devices in all versions prior to V3.0 (e.g., 7KG8500 variants) rely on a challenge-response authentication mechanism during unencrypted communication. The challenge space is limited, meaning the same challenge value can reappear after a relatively small number of requests [1][2]. This flaw allows an attacker to capture a valid challenge-response pair and use it later for replay.

Exploitation

An unauthenticated attacker with network access to the device can passively eavesdrop on the unencrypted challenge-response exchange between a legitimate user and the device. By capturing a valid pair and then repeatedly requesting the web interface (e.g., sending many login page requests), the attacker waits until the same challenge value reappears. When it does, the attacker replays the captured response to authenticate successfully [1]. No prior authentication or user interaction beyond the initial capture is required, and the attack can be automated.

Impact

Upon successful replay, the attacker gains unauthorized access to the management interface of the SICAM T device. Depending on the privileges of the original user whose credentials were captured, the attacker may be able to read sensitive configuration data, modify device settings, or disrupt operations. This can lead to full compromise of the device's configuration and control functions [2].

Mitigation

Siemens has released firmware version V3.00 for SICAM T (and SICAM P850/P855) which resolves this issue. Customers should update to V3.00 or later, available via Siemens support portal [1]. As a workaround, restrict network access to the device's web interface (port 443/tcp) to only trusted IP addresses and avoid accessing untrusted links while logged in [2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.