CVE-2022-30231
MEDIUMSICAM GridEdge (Classic) <V2.6.6 - Info Disclosure
Title source: llmDescription
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application discloses password hashes of other users upon request. This could allow an authenticated user to retrieve another user's password hash.
Scores
CVSS v3
4.9
EPSS
0.0019
EPSS Percentile
40.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
CWE-402
Status
published
Affected Products (4)
siemens/sicam_gridedge_essential
< 2.6.6
siemens/sicam_gridedge_essential
< 2.6.6
siemens/sicam_gridedge_essential
< 2.6.6
siemens/sicam_gridedge_essential
< 2.6.6
Timeline
Published
Jun 14, 2022
Tracked Since
Feb 18, 2026