Insufficient Session Expiration in Siemens products - CVE-2022-24042
Published: May 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the web application returns an AuthToken that does not expire at the defined auto logoff delay timeout. A remote non-authenticated attacker can obtain or guess session token and gain unauthorized access to session that belongs to another user.
Affected software
Desigo DXR2
Desigo PXC4
Desigo PXC5
How to mitigate CVE-2022-24042
Desigo DXR2 - update to 01.21.142.5-22
Desigo PXC4 - update to 02.20.142.10-10884
Desigo PXC5 - update to 02.20.142.10-10884