Use of Password Hash With Insufficient Computational Effort in Siemens products - CVE-2022-24041
Published: May 11, 2022
Vulnerability identifier: #VU63061
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24041
CWE-ID: CWE-916
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the web application stores the PBKDF2 derived key of users passwords with a low iteration count. A remote user can gain unauthorized access to sensitive information on the system.
Affected software
Desigo PXC3
Desigo DXR2
Desigo PXC4
Desigo PXC5
Desigo DXR2
Desigo PXC4
Desigo PXC5
How to mitigate CVE-2022-24041
Install updates from vendor's website.
Desigo PXC3 - update to 01.21.142.4-1
Desigo DXR2 - update to 01.21.142.5-22
Desigo PXC4 - update to 02.20.142.10-10884
Desigo PXC5 - update to 02.20.142.10-10884
Desigo DXR2 - update to 01.21.142.5-22
Desigo PXC4 - update to 02.20.142.10-10884
Desigo PXC5 - update to 02.20.142.10-10884