PT-2022-3046 · Siemens · Desigo Cc Compact+4
Published
2022-06-21
·
Updated
2024-02-13
·
CVE-2022-33139
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cerberus DMS versions all
Desigo CC versions all
Desigo CC Compact versions all
SIMATIC WinCC OA V3.16 versions all
SIMATIC WinCC OA V3.17 versions all
SIMATIC WinCC OA V3.18 versions all
Description
A vulnerability has been identified in the affected applications, which use client-side only authentication when neither server-side authentication (SSA) nor Kerberos authentication is enabled. This configuration allows attackers to impersonate other users or exploit the client-server protocol without being authenticated.
Recommendations
For Cerberus DMS, consider enabling server-side authentication (SSA) or Kerberos authentication to mitigate the risk.
For Desigo CC, consider enabling server-side authentication (SSA) or Kerberos authentication to mitigate the risk.
For Desigo CC Compact, consider enabling server-side authentication (SSA) or Kerberos authentication to mitigate the risk.
For SIMATIC WinCC OA V3.16, consider changing the configuration to enable server-side authentication (SSA) or Kerberos authentication.
For SIMATIC WinCC OA V3.17, consider changing the configuration to enable server-side authentication (SSA) or Kerberos authentication.
For SIMATIC WinCC OA V3.18, consider changing the configuration to enable server-side authentication (SSA) or Kerberos authentication.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Desigo Cc
Desigo Cc Compact
Simatic Wincc Oa V3.16
Simatic Wincc Oa V3.17
Simatic Wincc Oa V3.18