Cross-Site Request Forgery in Siemens Desigo Products
CVE-2022-40179
8.1HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 11 October 2022
What is CVE-2022-40179?
A vulnerability exists in Siemens Desigo products where a Cross-Site Request Forgery flaw allows remote attackers to execute arbitrary Axon queries without authentication. This occurs due to inadequate anti-CSRF token validation in the web application's operation endpoints. Attackers can trick users into clicking on malicious links or visiting crafted web pages while they are logged into the application, thereby compromising the device.
Affected Version(s)
Desigo PXM30-1 All versions < V02.20.126.11-41
Desigo PXM30.E All versions < V02.20.126.11-41
Desigo PXM40-1 All versions < V02.20.126.11-41