Cross-Site Request Forgery in Siemens Desigo Products
CVE-2022-40179
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 11 October 2022
What is CVE-2022-40179?
A vulnerability exists in Siemens Desigo products where a Cross-Site Request Forgery flaw allows remote attackers to execute arbitrary Axon queries without authentication. This occurs due to inadequate anti-CSRF token validation in the web application's operation endpoints. Attackers can trick users into clicking on malicious links or visiting crafted web pages while they are logged into the application, thereby compromising the device.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Desigo PXM30-1 All versions < V02.20.126.11-41
Desigo PXM30.E All versions < V02.20.126.11-41
Desigo PXM40-1 All versions < V02.20.126.11-41
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved