Username Enumeration Vulnerability in Siemens Desigo Products
CVE-2022-24043
5.3MEDIUM
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 20 May 2022
What is CVE-2022-24043?
A vulnerability has been identified in Siemens' Desigo product line, affecting multiple versions of the DXR2, PXC3, PXC4, and PXC5 models. The issue arises from improper normalization of response times during login attempts, allowing a remote unauthenticated attacker to distinguish between successful and failed login attempts based on their timing. This could facilitate a username enumeration attack, enabling attackers to ascertain valid usernames and potentially facilitating further attacks on the system.
Affected Version(s)
Desigo DXR2 All versions < V01.21.142.5-22
Desigo PXC3 All versions < V01.21.142.4-18
Desigo PXC4 All versions < V02.20.142.10-10884