CVE-2022-24041

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application stores the PBKDF2 derived key of users passwords with a low iteration count. An attacker with user profile access privilege can retrieve the stored password hashes of other accounts and then successfully perform an offline cracking attack and recover the plaintext passwords of other users.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
siemensCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
VendorProductVersion
siemensdesigo_pxc5_firmware
𝑥
< 02.20.142.10-10884
siemensdesigo_pxc4_firmware
𝑥
< 02.20.142.10-10884
siemensdesigo_pxc3_firmware
𝑥
< 01.21.142.4-18
siemensdesigo_dxr2_firmware
𝑥
< 01.21.142.5-22
𝑥
= Vulnerable software versions