Denial of Service Vulnerability in Desigo DXR2, PXC3, PXC4, and PXC5 by Siemens
CVE-2022-24040
6.5MEDIUM
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 10 May 2022
Summary
A vulnerability exists in several Desigo products from Siemens, where the web application does not enforce an upper limit on the PBKDF2 key derivation cost factor during account creation or updates. This flaw allows attackers with user profile access to exploit the system by setting an excessively high cost factor, leading to significant CPU consumption and potentially causing a denial of service. Such attacks can severely impact system availability and performance.
Affected Version(s)
Desigo DXR2 All versions < V01.21.142.5-22
Desigo PXC3 All versions < V01.21.142.4-18
Desigo PXC4 All versions < V02.20.142.10-10884
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved