PT-2022-3046 · Siemens · Desigo Cc Compact+4

Published

2022-06-21

·

Updated

2024-02-13

·

CVE-2022-33139

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cerberus DMS versions all Desigo CC versions all Desigo CC Compact versions all SIMATIC WinCC OA V3.16 versions all SIMATIC WinCC OA V3.17 versions all SIMATIC WinCC OA V3.18 versions all
Description A vulnerability has been identified in the affected applications, which use client-side only authentication when neither server-side authentication (SSA) nor Kerberos authentication is enabled. This configuration allows attackers to impersonate other users or exploit the client-server protocol without being authenticated.
Recommendations For Cerberus DMS, consider enabling server-side authentication (SSA) or Kerberos authentication to mitigate the risk. For Desigo CC, consider enabling server-side authentication (SSA) or Kerberos authentication to mitigate the risk. For Desigo CC Compact, consider enabling server-side authentication (SSA) or Kerberos authentication to mitigate the risk. For SIMATIC WinCC OA V3.16, consider changing the configuration to enable server-side authentication (SSA) or Kerberos authentication. For SIMATIC WinCC OA V3.17, consider changing the configuration to enable server-side authentication (SSA) or Kerberos authentication. For SIMATIC WinCC OA V3.18, consider changing the configuration to enable server-side authentication (SSA) or Kerberos authentication.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2022-03715
CVE-2022-33139

Affected Products

Desigo Cc
Desigo Cc Compact
Simatic Wincc Oa V3.16
Simatic Wincc Oa V3.17
Simatic Wincc Oa V3.18