Vulnerability in Siemens Desigo PXM and PXG Series Products
CVE-2022-40181

8.3HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
11 October 2022

Summary

A security flaw exists in various Siemens Desigo PXM and PXG series products where the embedded browser inadequately restricts interactions with alternative URI schemes. This vulnerability allows a remote attacker with low privileges to exploit this weakness by manipulating the homepage or redirecting users through JavaScript. As a result, they could read arbitrary files from the device's filesystem, execute malicious JavaScript that compromises user data, or even trigger denial of service conditions, raising serious concerns for system integrity and data privacy.

Affected Version(s)

Desigo PXM30-1 All versions < V02.20.126.11-41

Desigo PXM30.E All versions < V02.20.126.11-41

Desigo PXM40-1 All versions < V02.20.126.11-41

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.