Lucene search

K
cve[email protected]CVE-2022-33139
HistoryJun 21, 2022 - 1:15 p.m.

CVE-2022-33139

2022-06-2113:15:08
CWE-287
CWE-603
web.nvd.nist.gov
41
4
cve-2022-33139
vulnerability
cerberus dms
desigo cc
simatic wincc oa
authentication
exploit
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.2%

A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-default configuration), SIMATIC WinCC OA V3.18 (All versions in non-default configuration). Affected applications use client-side only authentication, when neither server-side authentication (SSA) nor Kerberos authentication is enabled. In this configuration, attackers could impersonate other users or exploit the client-server protocol without being authenticated.

Affected configurations

NVD
Node
siemenscerberus_dms
OR
siemensdesigo_cc
OR
siemensdesigo_cc_compact
OR
siemenswincc_open_architectureMatch3.16
OR
siemenswincc_open_architectureMatch3.17
OR
siemenswincc_open_architectureMatch3.18

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "Cerberus DMS",
    "versions": [
      {
        "version": "All versions",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Siemens",
    "product": "Desigo CC",
    "versions": [
      {
        "version": "All versions",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Siemens",
    "product": "Desigo CC Compact",
    "versions": [
      {
        "version": "All versions",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC WinCC OA V3.16",
    "versions": [
      {
        "version": "All versions in default configuration",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC WinCC OA V3.17",
    "versions": [
      {
        "version": "All versions in non-default configuration",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC WinCC OA V3.18",
    "versions": [
      {
        "version": "All versions in non-default configuration",
        "status": "affected"
      }
    ]
  }
]

Social References

More

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.2%

Related for CVE-2022-33139