6.5

CVE-2022-24041

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application stores the PBKDF2 derived key of users passwords with a low iteration count. An attacker with user profile access privilege can retrieve the stored password hashes of other accounts and then successfully perform an offline cracking attack and recover the plaintext passwords of other users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Desigo Pxc5 Firmware Version < 02.20.142.10-10884
   Siemens ≫ Desigo Pxc5 Version -
Siemens ≫ Desigo Pxc4 Firmware Version < 02.20.142.10-10884
   Siemens ≫ Desigo Pxc4 Version -
Siemens ≫ Desigo Pxc3 Firmware Version < 01.21.142.4-18
   Siemens ≫ Desigo Pxc3 Version -
Siemens ≫ Desigo Dxr2 Firmware Version < 01.21.142.5-22
   Siemens ≫ Desigo Dxr2 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.376
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-916 Use of Password Hash With Insufficient Computational Effort

The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

https://cert-portal.siemens.com/productcert/pdf/ssa-626968.pdf
Vendor Advisory