Insufficient Session Expiration in Siemens products - CVE-2022-24042

 

Insufficient Session Expiration in Siemens products - CVE-2022-24042

Published: May 11, 2022


Vulnerability identifier: #VU63064
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24042
CWE-ID: CWE-613
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to the web application returns an AuthToken that does not expire at the defined auto logoff delay timeout. A remote non-authenticated attacker can obtain or guess session token and gain unauthorized access to session that belongs to another user.


Affected software

Desigo PXC3
Desigo DXR2
Desigo PXC4
Desigo PXC5

How to mitigate CVE-2022-24042

Install updates from vendor's website.

Desigo PXC3 - update to 01.21.142.4-1
Desigo DXR2 - update to 01.21.142.5-22
Desigo PXC4 - update to 02.20.142.10-10884
Desigo PXC5 - update to 02.20.142.10-10884

External References

Related Security Bulletins