CVE-2022-29880
Description
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly validate input in the configuration interface. This could allow an authenticated attacker to place persistent XSS attacks to perform arbitrary actions in the name of a logged user which accesses the affected views.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2022-29880: Stored XSS in SICAM T configuration interface allows authenticated attackers to impersonate logged-in users.
Vulnerability
The vulnerability CVE-2022-29880 affects SICAM T (all versions before V3.0). The configuration interface does not properly validate input, allowing an authenticated attacker to inject persistent cross-site scripting (XSS) payloads. This affects the web interface of the device. [1][2]
Exploitation
An attacker must be authenticated to the device. They can then inject malicious script code into the configuration interface input fields, which is persistently stored. When another logged-in user accesses the affected views, the stored script executes in the user's browser context. The attacker does not require additional network access beyond the authenticated session. [1][2]
Impact
Successful exploitation allows the attacker to perform arbitrary actions in the browser context of a victim user who visits the affected views. This can lead to session hijacking, unauthorized configuration changes, data theft, or other actions as the victim user. The impact is limited to the privileges of the victim user. [1][2]
Mitigation
Siemens has released SICAM T V3.0, which fixes this vulnerability. Users should update to version V3.0 or later. As a workaround, restrict access to the web interface (port 443/tcp) to trusted IP addresses only, and instruct users not to follow links from untrusted sources while logged in. [1][2]
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <3.0
- Siemens/SICAM Tv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.