A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbuilt SQL server in cleartext. In combination with the by default enabled xp_cmdshell feature unauthenticated remote attackers could execute custom OS commands. At the time of assigning the CVE, the affected firmware version of the component has already been superseded by succeeding mainline versions.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2022-12-13T00:00:00
Updated: 2024-08-03T13:40:06.447Z
Reserved: 2022-10-24T00:00:00
Link: CVE-2022-43724
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-12-13T16:15:24.327
Modified: 2024-11-21T07:27:08.317
Link: CVE-2022-43724
Redhat
No data.