VYPR
Unrated severityNVD Advisory· Published May 10, 2022· Updated Dec 9, 2025

CVE-2022-29883

CVE-2022-29883

Description

A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pages of the web interface. This could allow an attacker to delete log files without authentication.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SICAM T before V3.0 allows unauthenticated access to the web interface, enabling an attacker to delete log files.

Vulnerability

A vulnerability exists in the web interface of SICAM T devices (all versions prior to V3.0) [2]. The affected devices do not restrict unauthenticated access to certain pages of the web interface, allowing an attacker to reach functionality that should require authentication [2]. This has been identified with a CVSS v3.1 base score of 9.9 [2].

Exploitation

An attacker with network access to the device can exploit this vulnerability without any authentication, user interaction, or special privileges [2]. By directly accessing unprotected pages of the web interface, the attacker can perform actions that should be restricted to authenticated users. The attack complexity is low [2].

Impact

Successful exploitation allows an attacker to delete log files on the device without authentication [2]. This could hinder forensic analysis after an attack. More broadly, this unauthenticated access to web interface functionality may lead to further impacts, including remote code execution, denial of service, and session hijacking (the full scope of vulnerabilities in this component) [2].

Mitigation

Siemens has released version V3.0 of SICAM T to address this vulnerability [2]. Users should update to V3.0 or later. As a workaround, restrict access to port 443/tcp (HTTPS) to trusted IP addresses only [2]. Additionally, do not access links from untrusted sources while logged into SICAM T [2].

References
  1. SSA-471761

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.