CVE-2022-33137
—CVSS 3.1
8.0 high
EPSS
<1%p56
Published
()
Modified
Description
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMATIC MV560 X (All versions < V3.3). The web session management of affected devices does not invalidate session ids in certain logout scenarios. This could allow an authenticated remote attacker to hijack other users' sessions.
- Vendors
- siemens
- Products
- simatic mv540 h firmware, simatic mv540 s firmware, simatic mv550 h firmware, simatic mv550 s firmware, simatic mv560 u firmware, simatic mv560 x firmware
- Weakness
- CWE-613
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.