Cross-Site Request Forgery Vulnerability in Siemens Web Services
CVE-2022-30694

6.5MEDIUM

What is CVE-2022-30694?

An issue in the login endpoint of Siemens web services permits inadequate origin checking, allowing authenticated remote attackers to potentially exploit this weakness. By leveraging this vulnerability, attackers can orchestrate cross-site request forgery (CSRF) attacks, which could enable them to track the activities of legitimate users without their consent.

Affected Version(s)

SIMATIC Drive Controller CPU 1504D TF All versions < V2.9.7

SIMATIC Drive Controller CPU 1507D TF All versions < V2.9.7

SIMATIC ET 200pro IM154-8 PN/DP CPU All versions < V3.2.19

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.