CVE-2022-24044

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The login functionality of the application does not employ any countermeasures against Password Spraying attacks or Credential Stuffing attacks. An attacker could obtain a list of valid usernames on the device by exploiting the issue and then perform a precise Password Spraying or Credential Stuffing attack in order to obtain access to at least one account.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:desigo_dxr2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:desigo_dxr2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:desigo_pxc3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:desigo_pxc3:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:desigo_pxc4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:desigo_pxc4:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:desigo_pxc5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:desigo_pxc5:-:*:*:*:*:*:*:*

History

01 Jun 2022, 15:28

Type Values Removed Values Added
First Time Siemens desigo Pxc3 Firmware
Siemens desigo Pxc4
Siemens desigo Pxc3
Siemens desigo Pxc4 Firmware
Siemens
Siemens desigo Pxc5 Firmware
Siemens desigo Dxr2 Firmware
Siemens desigo Dxr2
Siemens desigo Pxc5
CPE cpe:2.3:h:siemens:desigo_dxr2:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:desigo_dxr2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:desigo_pxc4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:desigo_pxc3:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:desigo_pxc5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:desigo_pxc5:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:desigo_pxc4:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:desigo_pxc3_firmware:*:*:*:*:*:*:*:*
CWE CWE-307
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
References (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-626968.pdf - (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-626968.pdf - Vendor Advisory

20 May 2022, 14:15

Type Values Removed Values Added
Summary A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The login functionality of the application does not employ any countermeasures against Password Spraying attacks or Credential Stuffing attacks. An attacker could obtain a list of valid usernames on the device by exploiting the issue and then perform a precise Password Spraying or Credential Stuffing attack in order to obtain access to at least one account. A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The login functionality of the application does not employ any countermeasures against Password Spraying attacks or Credential Stuffing attacks. An attacker could obtain a list of valid usernames on the device by exploiting the issue and then perform a precise Password Spraying or Credential Stuffing attack in order to obtain access to at least one account.

20 May 2022, 13:43

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-20 13:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-24044

Mitre link : CVE-2022-24044

CVE.ORG link : CVE-2022-24044


JSON object : View

Products Affected

siemens

  • desigo_pxc3_firmware
  • desigo_dxr2
  • desigo_pxc4
  • desigo_pxc3
  • desigo_pxc5_firmware
  • desigo_pxc4_firmware
  • desigo_pxc5
  • desigo_dxr2_firmware
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts