Lucene search

K
cveSiemensCVE-2022-24042
HistoryMay 10, 2022 - 11:15 a.m.

CVE-2022-24042

2022-05-1011:15:08
CWE-613
siemens
web.nvd.nist.gov
71
5
cve-2022-24042
desigo dxr2
desigo pxc3
desigo pxc4
desigo pxc5
web application security
unauthorized access
nvd

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

45.8%

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application returns an AuthToken that does not expire at the defined auto logoff delay timeout. An attacker could be able to capture this token and re-use old session credentials or session IDs for authorization.

Affected configurations

Nvd
Node
siemensdesigo_pxc5_firmwareRange<02.20.142.10-10884
AND
siemensdesigo_pxc5Match-
Node
siemensdesigo_pxc4_firmwareRange<02.20.142.10-10884
AND
siemensdesigo_pxc4Match-
Node
siemensdesigo_pxc3_firmwareRange<01.21.142.4-18
AND
siemensdesigo_pxc3Match-
Node
siemensdesigo_dxr2_firmwareRange<01.21.142.5-22
AND
siemensdesigo_dxr2Match-
VendorProductVersionCPE
siemensdesigo_pxc5_firmware*cpe:2.3:o:siemens:desigo_pxc5_firmware:*:*:*:*:*:*:*:*
siemensdesigo_pxc5-cpe:2.3:h:siemens:desigo_pxc5:-:*:*:*:*:*:*:*
siemensdesigo_pxc4_firmware*cpe:2.3:o:siemens:desigo_pxc4_firmware:*:*:*:*:*:*:*:*
siemensdesigo_pxc4-cpe:2.3:h:siemens:desigo_pxc4:-:*:*:*:*:*:*:*
siemensdesigo_pxc3_firmware*cpe:2.3:o:siemens:desigo_pxc3_firmware:*:*:*:*:*:*:*:*
siemensdesigo_pxc3-cpe:2.3:h:siemens:desigo_pxc3:-:*:*:*:*:*:*:*
siemensdesigo_dxr2_firmware*cpe:2.3:o:siemens:desigo_dxr2_firmware:*:*:*:*:*:*:*:*
siemensdesigo_dxr2-cpe:2.3:h:siemens:desigo_dxr2:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Desigo DXR2",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V01.21.142.5-22"
      }
    ]
  },
  {
    "product": "Desigo PXC3",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V01.21.142.4-18"
      }
    ]
  },
  {
    "product": "Desigo PXC4",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V02.20.142.10-10884"
      }
    ]
  },
  {
    "product": "Desigo PXC5",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V02.20.142.10-10884"
      }
    ]
  }
]

Social References

More

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

45.8%

Related for CVE-2022-24042