PT-2022-25294 · Siemens · Sicam P850+1
Published
2022-10-11
·
Updated
2023-06-13
·
CVE-2022-40226
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SICAM P850 versions prior to V3.10
SICAM P855 versions prior to V3.10
Description
A vulnerability has been identified in the affected devices, which accept user-defined session cookies and do not renew the session cookie after login/logout. This could allow an attacker to take over another user's session after login.
Recommendations
For SICAM P850 versions prior to V3.10, update to version V3.10 or later to resolve the issue.
For SICAM P855 versions prior to V3.10, update to version V3.10 or later to resolve the issue.
As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of session takeover until a patch is available.
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sicam P850
Sicam P855