VYPR
Unrated severityNVD Advisory· Published May 10, 2022· Updated Dec 9, 2025

CVE-2022-29880

CVE-2022-29880

Description

A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly validate input in the configuration interface. This could allow an authenticated attacker to place persistent XSS attacks to perform arbitrary actions in the name of a logged user which accesses the affected views.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2022-29880: Stored XSS in SICAM T configuration interface allows authenticated attackers to impersonate logged-in users.

Vulnerability

The vulnerability CVE-2022-29880 affects SICAM T (all versions before V3.0). The configuration interface does not properly validate input, allowing an authenticated attacker to inject persistent cross-site scripting (XSS) payloads. This affects the web interface of the device. [1][2]

Exploitation

An attacker must be authenticated to the device. They can then inject malicious script code into the configuration interface input fields, which is persistently stored. When another logged-in user accesses the affected views, the stored script executes in the user's browser context. The attacker does not require additional network access beyond the authenticated session. [1][2]

Impact

Successful exploitation allows the attacker to perform arbitrary actions in the browser context of a victim user who visits the affected views. This can lead to session hijacking, unauthorized configuration changes, data theft, or other actions as the victim user. The impact is limited to the privileges of the victim user. [1][2]

Mitigation

Siemens has released SICAM T V3.0, which fixes this vulnerability. Users should update to version V3.0 or later. As a workaround, restrict access to the web interface (port 443/tcp) to trusted IP addresses only, and instruct users not to follow links from untrusted sources while logged in. [1][2]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.