Client-Side Authentication Vulnerability in Cerberus DMS and Desigo Products by Siemens
CVE-2022-33139
9.8CRITICAL
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 21 June 2022
What is CVE-2022-33139?
A vulnerability has been discovered in various Siemens products, including Cerberus DMS and Desigo systems, which utilize client-side only authentication. When server-side authentication or Kerberos is not activated, attackers can potentially masquerade as legitimate users or manipulate the client-server communication protocol without proper authentication checks. This flaw emphasizes the critical importance of implementing robust authentication mechanisms in both default and non-default configurations of affected products to safeguard against unauthorized access and exploitation.
Affected Version(s)
Cerberus DMS All versions
Desigo CC All versions
Desigo CC Compact All versions