ZeroHour

CVE-2022-30694

CVSS 3.1
6.5 medium
EPSS
<1%p24
Published
()
Modified
Description

The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.

Vendors
siemens
Products
simatic s7-1500 software controller, simatic s7-plcsim advanced, simatic wincc runtime, 6es7154-8fb01-0ab0 firmware, 6es7154-8ab01-0ab0 firmware, 6es7154-8fx00-0ab0 firmware, 6es7151-8ab01-0ab0 firmware, 6es7151-8fb01-0ab0 firmware, 6es7314-6eh04-0ab0 firmware, 6es7315-2eh14-0ab0 firmware, 6es7315-2fj14-0ab0 firmware, 6es7315-7tj10-0ab0 firmware
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.