PT-2022-2719 · Siemens · Desigo Pxc3+3

Published

2022-05-10

·

Updated

2022-06-01

·

CVE-2022-24044

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Desigo DXR2 versions prior to V01.21.142.5-22 Desigo PXC3 versions prior to V01.21.142.4-18 Desigo PXC4 versions prior to V02.20.142.10-10884 Desigo PXC5 versions prior to V02.20.142.10-10884
Description The issue is related to the lack of authentication attempt restrictions in the software of Desigo DXR2, PXC3, PXC4, and PXC5 modules. This could allow a remote attacker to gain unauthorized access to protected information by capturing lists of usernames and/or email addresses along with corresponding passwords. The login functionality does not employ countermeasures against Password Spraying or Credential Stuffing attacks, enabling an attacker to obtain valid usernames and then perform a precise attack to gain access to at least one account.
Recommendations For Desigo DXR2 versions prior to V01.21.142.5-22, update to version V01.21.142.5-22 or later to resolve the issue. For Desigo PXC3 versions prior to V01.21.142.4-18, update to version V01.21.142.4-18 or later to resolve the issue. For Desigo PXC4 versions prior to V02.20.142.10-10884, update to version V02.20.142.10-10884 or later to resolve the issue. For Desigo PXC5 versions prior to V02.20.142.10-10884, update to version V02.20.142.10-10884 or later to resolve the issue.

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03223
CVE-2022-24044

Affected Products

Desigo Dxr2
Desigo Pxc3
Desigo Pxc4
Desigo Pxc5