Improper access control in Siemens products - CVE-2022-46354
Published: December 16, 2022
SCALANCE X204RNA (HSR)
SCALANCE X204RNA (PRP)
SCALANCE X204RNA EEC (HSR)
SCALANCE X204RNA EEC (PRP)
SCALANCE X204RNA EEC (PRP/HSR)
Siemens
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the webserver. A remote attacker on the local network can bypass implemented security restrictions and extract confidential session information under certain circumstances.