Session Hijacking Vulnerability in Siemens SIMATIC MV Series
CVE-2022-33137
8HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 12 July 2022
What is CVE-2022-33137?
A vulnerability in the web session management of the Siemens SIMATIC MV series devices allows an authenticated remote attacker to hijack the sessions of other users. This issue occurs because the session identifiers are not properly invalidated in certain logout scenarios, posing a significant risk to user account safety. Affected versions include all versions of SIMATIC MV540 H, MV540 S, MV550 H, MV550 S, MV560 U, and MV560 X prior to V3.3.
Affected Version(s)
SIMATIC MV540 H All versions < V3.3
SIMATIC MV540 S All versions < V3.3
SIMATIC MV550 H All versions < V3.3