A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V16), SICAM A8000 CP-8021 (All versions < V16), SICAM A8000 CP-8022 (All versions < V16). A web server misconfiguration of the affected device can cause insecure ciphers usage by a userĀ“s browser. An attacker in a privileged position could decrypt the communication and compromise confidentiality and integrity of the transmitted information.
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-415783.pdf | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-062/ | Not Applicable |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: siemens
Published: 2020-12-14T21:05:19
Updated: 2021-01-14T17:06:09
Reserved: 2020-11-10T00:00:00
Link: CVE-2020-28396
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-12-14T21:15:21.067
Modified: 2022-08-06T03:53:39.417
Link: CVE-2020-28396
JSON object: View
Redhat Information
No data.