Session Management Vulnerability in Siemens Desigo Products
CVE-2022-24042

9.1CRITICAL

Key Information:

Vendor
Siemens
Vendor
CVE Published:
10 May 2022

Summary

A session management vulnerability in Siemens' Desigo products permits the web application to return an AuthToken that does not expire according to the defined auto logoff delay. This flaw allows attackers to capture the AuthToken and potentially reuse outdated session credentials or session IDs for unauthorized access. Affected versions include Desigo DXR2, PXC3, PXC4, and PXC5, making it critical for users to update to the latest versions to mitigate this risk. For detailed information, refer to the product certification document.

Affected Version(s)

Desigo DXR2 All versions < V01.21.142.5-22

Desigo PXC3 All versions < V01.21.142.4-18

Desigo PXC4 All versions < V02.20.142.10-10884

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.