Denial of Service Vulnerability in Desigo DXR2, PXC3, PXC4, and PXC5 by Siemens
CVE-2022-24040
6.5MEDIUM
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 10 May 2022
What is CVE-2022-24040?
A vulnerability exists in several Desigo products from Siemens, where the web application does not enforce an upper limit on the PBKDF2 key derivation cost factor during account creation or updates. This flaw allows attackers with user profile access to exploit the system by setting an excessively high cost factor, leading to significant CPU consumption and potentially causing a denial of service. Such attacks can severely impact system availability and performance.
Affected Version(s)
Desigo DXR2 All versions < V01.21.142.5-22
Desigo PXC3 All versions < V01.21.142.4-18
Desigo PXC4 All versions < V02.20.142.10-10884