8.8

CVE-2022-31765

Affected devices do not properly authorize the change password function of the web interface.
This could allow low privileged users to escalate their privileges.

Data is provided by the National Vulnerability Database (NVD)
Siemens6gk6108-4am00-2ba2 Firmware Version < 7.1.2
   Siemens6gk6108-4am00-2ba2 Version-
Siemens6gk6108-4am00-2da2 Firmware Version < 7.1.2
   Siemens6gk6108-4am00-2da2 Version-
Siemens6gk5804-0ap00-2aa2 Firmware Version < 7.1.2
   Siemens6gk5804-0ap00-2aa2 Version-
Siemens6gk5812-1aa00-2aa2 Firmware Version < 7.1.2
   Siemens6gk5812-1aa00-2aa2 Version-
Siemens6gk5812-1ba00-2aa2 Firmware Version < 7.1.2
   Siemens6gk5812-1ba00-2aa2 Version-
Siemens6gk5816-1aa00-2aa2 Firmware Version < 7.1.2
   Siemens6gk5816-1aa00-2aa2 Version-
Siemens6gk5816-1ba00-2aa2 Firmware Version < 7.1.2
   Siemens6gk5816-1ba00-2aa2 Version-
Siemens6gk5826-2ab00-2ab2 Firmware Version < 7.1.2
   Siemens6gk5826-2ab00-2ab2 Version-
Siemens6gk5874-2aa00-2aa2 Firmware Version < 7.1.2
   Siemens6gk5874-2aa00-2aa2 Version-
Siemens6gk5874-3aa00-2aa2 Firmware Version < 7.1.2
   Siemens6gk5874-3aa00-2aa2 Version-
Siemens6gk5876-3aa02-2ba2 Firmware Version < 7.1.2
   Siemens6gk5876-3aa02-2ba2 Version-
Siemens6gk5876-3aa02-2ea2 Firmware Version < 7.1.2
   Siemens6gk5876-3aa02-2ea2 Version-
Siemens6gk5876-4aa00-2ba2 Firmware Version < 7.1.2
   Siemens6gk5876-4aa00-2ba2 Version-
Siemens6gk5876-4aa00-2da2 Firmware Version < 7.1.2
   Siemens6gk5876-4aa00-2da2 Version-
Siemens6gk5853-2ea00-2da1 Firmware Version < 7.1.2
   Siemens6gk5853-2ea00-2da1 Version-
Siemens6gk5856-2ea00-3da1 Firmware Version < 7.1.2
   Siemens6gk5856-2ea00-3da1 Version-
Siemens6gk5856-2ea00-3aa1 Firmware Version < 7.1.2
   Siemens6gk5856-2ea00-3aa1 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.18% 0.402
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
productcert@siemens.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.