Session Cookie Vulnerability in POWER METER SICAM Q200 by Siemens
CVE-2022-43398
What is CVE-2022-43398?
A vulnerability has been identified in the POWER METER SICAM Q200 family, where the devices fail to renew session cookies after user login/logout events and allow the acceptance of user-defined session cookies. This flaw enables an attacker to overwrite a legitimate user's session cookie, granting unauthorized access to the victim's account once they have logged in. The security implication of this vulnerability reflects a significant risk, as it could permit attackers to manipulate user sessions and potentially compromise sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
POWER METER SICAM Q100 All versions < V2.50
POWER METER SICAM Q100 All versions < V2.50
POWER METER SICAM Q100 All versions < V2.50
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved