A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do not require an user to be authenticated to access certain files. This could allow unauthenticated attackers to download these files.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-316850.pdf | patch vendor advisory |
http://seclists.org/fulldisclosure/2022/Apr/20 | third party advisory mailing list |
http://packetstormsecurity.com/files/166743/Siemens-A8000-CP-8050-CP-8031-SICAM-WEB-Missing-File-Download-Missing-Authentication.html | third party advisory vdb entry |