ICSA-22-167-08: Siemens SICAM GridEdge
CISA advisory · released 2022-06-14
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 2, 2025-11-11 (final)
CISA's summary
Summary: Multiple vulnerabilities were identified in the web server of the SICAM GridEdge application which includes missing authentication for critical API functions, absent cross-origin resource sharing restrictions and access to credentials. Siemens has released a new version for SICAM GridEdge (Classic) and recommends to update to the latest version.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | SICAM GridEdge (Classic) | vers:intdot/<2.6.6 |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2022-30228 — CVE-2022-30228 · CWE-346
The affected software does not apply cross-origin resource sharing (CORS) restrictions for critical operations. In case an attacker tricks a legitimate user into accessing a special resource a malicious request could be executed.
- CVE-2022-30229 — CVE-2022-30229 · CWE-306
The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to change data of a user, such as credentials, in case that user's id is known.
- CVE-2022-30230 — CVE-2022-30230 · CWE-306
The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to create a new user with administrative permissions.
- CVE-2022-30231 — CVE-2022-30231 · CWE-402
The affected application discloses password hashes of other users upon request. This could allow an authenticated user to retrieve another user's password hash.
Acknowledgments, as the advisory lists them
- Siemens ProductCERT: reporting these vulnerabilities to CISA.
- Abian Blome, Siemens Energy: reporting the vulnerabilities
The advisory's legal notice
The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.