PT-2022-3195 · Siemens · Desigo Pxc3+3

Published

2022-05-10

·

Updated

2022-06-01

·

CVE-2022-24043

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Desigo DXR2 versions prior to V01.21.142.5-22 Desigo PXC3 versions prior to V01.21.142.4-18 Desigo PXC4 versions prior to V02.20.142.10-10884 Desigo PXC5 versions prior to V02.20.142.10-10884
Description A vulnerability has been identified in the login functionality of the application, where it fails to normalize the response times of login attempts performed with wrong usernames and the ones executed with correct usernames. This allows a remote unauthenticated attacker to exploit this side-channel information and perform a username enumeration attack to identify valid usernames. The vulnerability is related to the disclosure of information through inconsistency, which can allow an attacker to gain unauthorized access to protected information by intercepting user name lists.
Recommendations For Desigo DXR2 versions prior to V01.21.142.5-22, update to version V01.21.142.5-22 or later. For Desigo PXC3 versions prior to V01.21.142.4-18, update to version V01.21.142.4-18 or later. For Desigo PXC4 versions prior to V02.20.142.10-10884, update to version V02.20.142.10-10884 or later. For Desigo PXC5 versions prior to V02.20.142.10-10884, update to version V02.20.142.10-10884 or later.

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03883
CVE-2022-24043

Affected Products

Desigo Dxr2
Desigo Pxc3
Desigo Pxc4
Desigo Pxc5