Session Cookie Vulnerability in Desigo Products from Siemens
CVE-2022-24045
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 20 May 2022
What is CVE-2022-24045?
A vulnerability has been identified in Siemens Desigo products, allowing session cookies to be set without security attributes such as 'Secure', 'HttpOnly', or 'SameSite'. This oversight permits the transmission of session cookies via unencrypted HTTP, making it possible for attackers to intercept and capture sensitive data over the network. Implementing secure configurations is essential to prevent unauthorized access and protect critical information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Desigo DXR2 All versions < V01.21.142.5-22
Desigo PXC3 All versions < V01.21.142.4-18
Desigo PXC4 All versions < V02.20.142.10-10884
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved