VYPR

Sicam Pas\/pqs

by Siemens Foundation

CVEs (12)

  • CVE-2022-43724CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbuilt SQL server in cleartext. In combination with the by default enabled xp_cmdshell feature unauthenticated remote attackers could execute…

  • CVE-2016-8567CriFeb 13, 2017
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the SICAM PAS installations. Attackers might gain privileged access to the database over Port 2638/TCP.

  • CVE-2016-9157CriDec 5, 2016
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially lead to unauthenticated remote code execution by sending specially crafted packets to port 19234/TCP.

  • CVE-2023-45205HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.20). The affected application is installed with specific files and folders with insecure permissions. This could allow an authenticated local attacker to inject arbitrary code and escalate…

  • CVE-2022-43722HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software does not properly secure a folder containing library files. This could allow an attacker to place a custom malicious DLL in this folder which is then run with SYSTEM rights when a…

  • CVE-2018-4858HigJul 9, 2018
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5 (affected as IEC 61850 system configurator is incorporated) (All versions < V7.80), DIGSI 4 (All versions < V4.93), SICAM PAS/PQS (All versions < V8.11), SICAM PQ Analyzer (All…

  • CVE-2016-8566HigFeb 13, 2017
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Siemens SICAM PAS before 8.00. Because of Storing Passwords in a Recoverable Format, an authenticated local attacker with certain privileges could possibly reconstruct the passwords of users for accessing the database.

  • CVE-2022-43723HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0), SICAM PAS/PQS (All versions >= 7.0 < V8.06). Affected software does not properly validate the input for a certain parameter in the s7ontcp.dll. This could allow an unauthenticated remote attacker to send…

  • CVE-2016-9156HigDec 5, 2016
    risk 0.48cvss 7.3epss 0.02

    A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts of the file system by sending specially crafted packets to port 19235/TCP.

  • CVE-2016-5848MedJul 4, 2016
    risk 0.44cvss 6.7epss 0.00

    Siemens SICAM PAS before 8.07 does not properly restrict password data in the database, which makes it easier for local users to calculate passwords by leveraging unspecified database privileges.

  • CVE-2023-38640MedOct 10, 2023
    risk 0.43cvss 6.6epss 0.00

    A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.22). The affected application is installed with specific files and folders with insecure permissions. This could allow an authenticated local attacker to read and modify configuration data in the…

  • CVE-2016-5849LowJul 4, 2016
    risk 0.16cvss 2.5epss 0.00

    Siemens SICAM PAS through 8.07 allows local users to obtain sensitive configuration information by leveraging database stoppage.