CVE-2022-33736
12.07.2022, 10:15
A vulnerability has been identified in Opcenter Quality V13.1 (All versions < V13.1.20220624), Opcenter Quality V13.2 (All versions < V13.2.20220624). The affected applications do not properly validate login information during authentication. This could lead to denial of service condition for existing users or allow unauthenticated remote attackers to successfully login without credentials.Enginsight
Vendor | Product | Version |
---|---|---|
siemens | opcenter_quality | 13.1.0 ≤ 𝑥 < 13.1.20220624 |
siemens | opcenter_quality | 13.2.0 ≤ 𝑥 < 13.2.20220624 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-303 - Incorrect Implementation of Authentication AlgorithmThe requirements for the software dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.