Description
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMATIC MV560 X (All versions < V3.3). The web session management of affected devices does not invalidate session ids in certain logout scenarios. This could allow an authenticated remote attacker to hijack other users' sessions.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-36188 | A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMATIC MV560 X (All versions < V3.3). The web session management of affected devices does not invalidate session ids in certain logout scenarios. This could allow an authenticated remote attacker to hijack other users' sessions. |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Siemens
Subscribe
Simatic Mv540 H
Subscribe
Simatic Mv540 H Firmware
Subscribe
Simatic Mv540 S
Subscribe
Simatic Mv540 S Firmware
Subscribe
Simatic Mv550 H
Subscribe
Simatic Mv550 H Firmware
Subscribe
Simatic Mv550 S
Subscribe
Simatic Mv550 S Firmware
Subscribe
Simatic Mv560 U
Subscribe
Simatic Mv560 U Firmware
Subscribe
Simatic Mv560 X
Subscribe
Simatic Mv560 X Firmware
Subscribe
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-08-03T08:01:19.904Z
Reserved: 2022-06-13T00:00:00.000Z
Link: CVE-2022-33137
No data.
Status : Modified
Published: 2022-07-12T10:15:10.707
Modified: 2024-11-21T07:07:35.047
Link: CVE-2022-33137
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD