Description
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMATIC MV560 X (All versions < V3.3). Affected devices do not perform authentication for several web API endpoints. This could allow an unauthenticated remote attacker to read and download data from the device.
Published: 2022-07-12
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-36189 A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMATIC MV560 X (All versions < V3.3). Affected devices do not perform authentication for several web API endpoints. This could allow an unauthenticated remote attacker to read and download data from the device.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00845}

epss

{'score': 0.00526}


Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00478}

epss

{'score': 0.00845}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00517}

epss

{'score': 0.00478}


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00579}

epss

{'score': 0.00517}


Subscriptions

Siemens Simatic Mv540 H Simatic Mv540 H Firmware Simatic Mv540 S Simatic Mv540 S Firmware Simatic Mv550 H Simatic Mv550 H Firmware Simatic Mv550 S Simatic Mv550 S Firmware Simatic Mv560 U Simatic Mv560 U Firmware Simatic Mv560 X Simatic Mv560 X Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2024-08-03T08:01:19.531Z

Reserved: 2022-06-13T00:00:00.000Z

Link: CVE-2022-33138

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-07-12T10:15:10.757

Modified: 2024-11-21T07:07:35.183

Link: CVE-2022-33138

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses