Description
A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). A Cross-Site Request Forgery exists in endpoints of the “Operation” web application that interpret and execute Axon language queries, due to the missing validation of anti-CSRF tokens or other origin checks. By convincing a victim to click on a malicious link or visit a specifically crafted webpage while logged-in to the device web application, a remote unauthenticated attacker can execute arbitrary Axon queries against the device.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-43482 | A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). A Cross-Site Request Forgery exists in endpoints of the “Operation” web application that interpret and execute Axon language queries, due to the missing validation of anti-CSRF tokens or other origin checks. By convincing a victim to click on a malicious link or visit a specifically crafted webpage while logged-in to the device web application, a remote unauthenticated attacker can execute arbitrary Axon queries against the device. |
References
History
No history.
Subscriptions
Siemens
Subscribe
Desigo Pxm30-1
Subscribe
Desigo Pxm30-1 Firmware
Subscribe
Desigo Pxm30.e
Subscribe
Desigo Pxm30.e Firmware
Subscribe
Desigo Pxm40-1
Subscribe
Desigo Pxm40-1 Firmware
Subscribe
Desigo Pxm40.e
Subscribe
Desigo Pxm40.e Firmware
Subscribe
Desigo Pxm50-1
Subscribe
Desigo Pxm50-1 Firmware
Subscribe
Desigo Pxm50.e
Subscribe
Desigo Pxm50.e Firmware
Subscribe
Pxg3.w100-1
Subscribe
Pxg3.w100-1 Firmware
Subscribe
Pxg3.w100-2
Subscribe
Pxg3.w100-2 Firmware
Subscribe
Pxg3.w200-1
Subscribe
Pxg3.w200-1 Firmware
Subscribe
Pxg3.w200-2
Subscribe
Pxg3.w200-2 Firmware
Subscribe
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-08-03T12:14:39.953Z
Reserved: 2022-09-08T00:00:00.000Z
Link: CVE-2022-40179
No data.
Status : Modified
Published: 2022-10-11T11:15:10.647
Modified: 2024-11-21T07:21:00.417
Link: CVE-2022-40179
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD