A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The login functionality of the application fails to normalize the response times of login attempts performed with wrong usernames with the ones executed with correct usernames. A remote unauthenticated attacker could exploit this side-channel information to perform a username enumeration attack and identify valid usernames.

Project Subscriptions

Vendors Products
Siemens Subscribe
Desigo Dxr2 Subscribe
Desigo Dxr2 Firmware Subscribe
Desigo Pxc3 Subscribe
Desigo Pxc3 Firmware Subscribe
Desigo Pxc4 Subscribe
Desigo Pxc4 Firmware Subscribe
Desigo Pxc5 Subscribe
Desigo Pxc5 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-28958 A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The login functionality of the application fails to normalize the response times of login attempts performed with wrong usernames with the ones executed with correct usernames. A remote unauthenticated attacker could exploit this side-channel information to perform a username enumeration attack and identify valid usernames.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2024-08-03T03:59:23.653Z

Reserved: 2022-01-27T00:00:00

Link: CVE-2022-24043

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-20T13:15:14.483

Modified: 2024-11-21T06:49:43.153

Link: CVE-2022-24043

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses