CVE-2022-31807
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
23/05/2025
Last modified:
09/12/2025
Description
A vulnerability has been identified in Building X - Security Manager Edge Controller (ACC-AP) (All versions). Affected devices do not properly check the integrity of firmware updates. This could allow a local attacker to upload a maliciously modified firmware onto the device. In a second scenario, a remote attacker who is able to intercept the transfer of a valid firmware from the server to the device could modify the firmware "on the fly".
Impact
Base Score 4.0
5.90
Severity 4.0
MEDIUM
Base Score 3.x
6.20
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:siemens:sipass_integrated_ac5102_\(acc-g2\)_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:sipass_integrated_ac5102_\(acc-g2\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:sipass_integrated_acc-ap_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:sipass_integrated_acc-ap:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



