Publication Date: 2022-06-14
Last Update: 2022-06-14
Current Version: V1.0
CVSS v3.1 Base Score: 10.0

Affected Product and Versions Remediation
SICAM GridEdge Essential ARM (6MD7881-2AA30):
All versions < V2.6.6
Update to V2.6.6 or later version
https://support.industry.siemens.com/cs/ww/en/view/109780559/
See further recommendations from section Workarounds and Mitigations
SICAM GridEdge Essential Intel (6MD7881-2AA40):
All versions < V2.6.6
Update to V2.6.6 or later version
https://support.industry.siemens.com/cs/ww/en/view/109780559/
See further recommendations from section Workarounds and Mitigations
SICAM GridEdge Essential with GDS ARM (6MD7881-2AA10):
All versions < V2.6.6
Update to V2.6.6 or later version
https://support.industry.siemens.com/cs/ww/en/view/109780559/
See further recommendations from section Workarounds and Mitigations
SICAM GridEdge Essential with GDS Intel (6MD7881-2AA20):
All versions < V2.6.6
Update to V2.6.6 or later version
https://support.industry.siemens.com/cs/ww/en/view/109780559/
See further recommendations from section Workarounds and Mitigations

CVSS v3.1 Base Score 9.6
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-346: Origin Validation Error

CVSS v3.1 Base Score 9.0
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-306: Missing Authentication for Critical Function

CVSS v3.1 Base Score 10.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-306: Missing Authentication for Critical Function

CVSS v3.1 Base Score 4.9
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
CWE: CWE-402: Transmission of Private Resources into a New Sphere (‘Resource Leak’)

https://www.siemens.com/cert/advisories