CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
Percentile
45.8%
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application returns an AuthToken that does not expire at the defined auto logoff delay timeout. An attacker could be able to capture this token and re-use old session credentials or session IDs for authorization.
Vendor | Product | Version | CPE |
---|---|---|---|
siemens | desigo_pxc5_firmware | * | cpe:2.3:o:siemens:desigo_pxc5_firmware:*:*:*:*:*:*:*:* |
siemens | desigo_pxc5 | - | cpe:2.3:h:siemens:desigo_pxc5:-:*:*:*:*:*:*:* |
siemens | desigo_pxc4_firmware | * | cpe:2.3:o:siemens:desigo_pxc4_firmware:*:*:*:*:*:*:*:* |
siemens | desigo_pxc4 | - | cpe:2.3:h:siemens:desigo_pxc4:-:*:*:*:*:*:*:* |
siemens | desigo_pxc3_firmware | * | cpe:2.3:o:siemens:desigo_pxc3_firmware:*:*:*:*:*:*:*:* |
siemens | desigo_pxc3 | - | cpe:2.3:h:siemens:desigo_pxc3:-:*:*:*:*:*:*:* |
siemens | desigo_dxr2_firmware | * | cpe:2.3:o:siemens:desigo_dxr2_firmware:*:*:*:*:*:*:*:* |
siemens | desigo_dxr2 | - | cpe:2.3:h:siemens:desigo_dxr2:-:*:*:*:*:*:*:* |
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
Percentile
45.8%