#VU63064 Insufficient Session Expiration in Siemens products - CVE-2022-24042
Published: May 11, 2022
Desigo DXR2
Desigo PXC3
Desigo PXC4
Desigo PXC5
Siemens
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the web application returns an AuthToken that does not expire at the defined auto logoff delay timeout. A remote non-authenticated attacker can obtain or guess session token and gain unauthorized access to session that belongs to another user.