CVE-2022-33139
A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-default configuration), SIMATIC WinCC OA V3.18 (All versions in non-default configuration). Affected applications use client-side only authentication, when neither server-side authentication (SSA) nor Kerberos authentication is enabled. In this configuration, attackers could impersonate other users or exploit the client-server protocol without being authenticated.
Published:Jun 21, 2022
Last Modified:Nov 21, 2024
EPS:Jun 21, 2022
EPSS Score:0.0039
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Siemens
Product
Cerberus Dms
Siemens
Cerberus Dms
Vendor
Siemens
Product
Desigo Cc
Siemens
Desigo Cc
Vendor
Siemens
Product
Desigo Cc Compact
Siemens
Desigo Cc Compact
Vendor
Siemens
Product
Wincc Open Architecture
Siemens
Wincc Open Architecture
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
