Insecure Session ID Generation in Siemens SCALANCE Products
CVE-2022-26647
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 12 July 2022
What is CVE-2022-26647?
A vulnerability exists in various Siemens SCALANCE devices, where the web server generates session IDs and nonces using insecure methods. This flaw allows unauthenticated remote attackers to potentially brute-force session IDs, leading to session hijacking. Users of affected products should promptly apply available patches to mitigate risks associated with this vulnerability. For detailed information, refer to the advisory from Siemens.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SCALANCE X200-4P IRT All versions < V5.5.2
SCALANCE X201-3P IRT All versions < V5.5.2
SCALANCE X201-3P IRT PRO All versions < V5.5.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved