PT-2022-2718 · Siemens · Desigo Pxc3+3
Published
2022-05-10
·
Updated
2023-06-23
·
CVE-2022-24045
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Desigo DXR2 versions prior to V01.21.142.5-22
Desigo PXC3 versions prior to V01.21.142.4-18
Desigo PXC4 versions prior to V02.20.142.10-10884
Desigo PXC5 versions prior to V02.20.142.10-10884
Description
The issue is related to the application setting session cookies on the browser via client-side JavaScript code without applying security attributes such as
Secure, HttpOnly, or SameSite. This allows an attacker to capture sensitive information by sniffing the network when a user browses the application via unencrypted HTTP protocol. The vulnerability can be exploited remotely, enabling an attacker to gain unauthorized access to protected information by intercepting session cookies.Recommendations
For Desigo DXR2 versions prior to V01.21.142.5-22, update to version V01.21.142.5-22 or later to resolve the issue.
For Desigo PXC3 versions prior to V01.21.142.4-18, update to version V01.21.142.4-18 or later to resolve the issue.
For Desigo PXC4 versions prior to V02.20.142.10-10884, update to version V02.20.142.10-10884 or later to resolve the issue.
For Desigo PXC5 versions prior to V02.20.142.10-10884, update to version V02.20.142.10-10884 or later to resolve the issue.
As a temporary workaround, consider using encrypted HTTPS protocol for browsing the application to minimize the risk of session cookie interception.
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Desigo Dxr2
Desigo Pxc3
Desigo Pxc4
Desigo Pxc5