Cross-Site Request Forgery Vulnerability in Siemens Web Services
CVE-2022-30694
6.5MEDIUM
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 8 November 2022
What is CVE-2022-30694?
An issue in the login endpoint of Siemens web services permits inadequate origin checking, allowing authenticated remote attackers to potentially exploit this weakness. By leveraging this vulnerability, attackers can orchestrate cross-site request forgery (CSRF) attacks, which could enable them to track the activities of legitimate users without their consent.
Affected Version(s)
SIMATIC Drive Controller CPU 1504D TF All versions < V2.9.7
SIMATIC Drive Controller CPU 1507D TF All versions < V2.9.7
SIMATIC ET 200pro IM154-8 PN/DP CPU All versions < V3.2.19