ZeroHour

CVE-2022-33137

CVSS 3.1
8.0 high
EPSS
<1%p56
Published
()
Modified
Description

A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMATIC MV560 X (All versions < V3.3). The web session management of affected devices does not invalidate session ids in certain logout scenarios. This could allow an authenticated remote attacker to hijack other users' sessions.

Vendors
siemens
Products
simatic mv540 h firmware, simatic mv540 s firmware, simatic mv550 h firmware, simatic mv550 s firmware, simatic mv560 u firmware, simatic mv560 x firmware
Weakness
CWE-613
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.