CVE-2022-30694
—CVSS 3.1
6.5 medium
EPSS
<1%p24
Published
()
Modified
Description
The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.
- Vendors
- siemens
- Products
- simatic s7-1500 software controller, simatic s7-plcsim advanced, simatic wincc runtime, 6es7154-8fb01-0ab0 firmware, 6es7154-8ab01-0ab0 firmware, 6es7154-8fx00-0ab0 firmware, 6es7151-8ab01-0ab0 firmware, 6es7151-8fb01-0ab0 firmware, 6es7314-6eh04-0ab0 firmware, 6es7315-2eh14-0ab0 firmware, 6es7315-2fj14-0ab0 firmware, 6es7315-7tj10-0ab0 firmware
- Weakness
- CWE-352
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.