6.5

CVE-2022-24045

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The application, after a successful login, sets the session cookie on the browser via client-side JavaScript code, without applying any security attributes (such as “Secure”, “HttpOnly”, or “SameSite”). Any attempts to browse the application via unencrypted HTTP protocol would lead to the transmission of all his/her session cookies in plaintext through the network. An attacker could then be able to sniff the network and capture sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Desigo Dxr2 Firmware Version < 01.21.142.5-22
   Siemens ≫ Desigo Dxr2 Version -
Siemens ≫ Desigo Pxc3 Firmware Version < 01.21.142.4-18
   Siemens ≫ Desigo Pxc3 Version -
Siemens ≫ Desigo Pxc4 Firmware Version < 02.20.142.10-10884
   Siemens ≫ Desigo Pxc4 Version -
Siemens ≫ Desigo Pxc5 Firmware Version < 02.20.142.10-10884
   Siemens ≫ Desigo Pxc5 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.59% 0.447
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-311 Missing Encryption of Sensitive Data

The product does not encrypt sensitive or critical information before storage or transmission.

CWE-614 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

The Secure attribute for sensitive cookies in HTTPS sessions is not set.

https://cert-portal.siemens.com/productcert/pdf/ssa-626968.pdf
Vendor Advisory