ZeroHour

CVE-2022-33138

CVSS 3.1
7.5 high
EPSS
1%p69
Published
()
Modified
Description

A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMATIC MV560 X (All versions < V3.3). Affected devices do not perform authentication for several web API endpoints. This could allow an unauthenticated remote attacker to read and download data from the device.

Vendors
siemens
Products
simatic mv540 h firmware, simatic mv540 s firmware, simatic mv550 h firmware, simatic mv550 s firmware, simatic mv560 u firmware, simatic mv560 x firmware
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.