CVE-2022-44731
Published on: Not Yet Published
Last Modified on: 01/10/2023 12:15:00 PM UTC
Certain versions of Simatic Wincc Oa from Siemens contain the following vulnerability:
A vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions < V3.15 P038), SIMATIC WinCC OA V3.16 (All versions < V3.16 P035), SIMATIC WinCC OA V3.17 (All versions < V3.17 P024), SIMATIC WinCC OA V3.18 (All versions < V3.18 P014). The affected component allows to inject custom arguments to the Ultralight Client backend application under certain circumstances. This could allow an authenticated remote attacker to inject arbitrary parameters when starting the client via the web interface (e.g., open attacker chosen panels with the attacker's credentials or start a Ctrl script).
- CVE-2022-44731 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Siemens - SIMATIC WinCC OA V3.15 version = All versions < V3.15 P038
- Affected Vendor/Software:
Siemens - SIMATIC WinCC OA V3.16 version = All versions < V3.16 P035
- Affected Vendor/Software:
Siemens - SIMATIC WinCC OA V3.17 version = All versions < V3.17 P024
- Affected Vendor/Software:
Siemens - SIMATIC WinCC OA V3.18 version = All versions < V3.18 P014
CVSS3 Score: 5.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
cert-portal.siemens.com application/pdf |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Siemens | Simatic Wincc Oa | 3.15 | All | All | All |
Application | Siemens | Simatic Wincc Oa | 3.16 | - | All | All |
Application | Siemens | Simatic Wincc Oa | 3.17 | - | All | All |
Application | Siemens | Simatic Wincc Oa | 3.18 | - | All | All |
- cpe:2.3:a:siemens:simatic_wincc_oa:3.15:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc_oa:3.16:-:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc_oa:3.17:-:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc_oa:3.18:-:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
cve.report/CVE-2022-44731 A vulnerability has been identified in SIMATIC WinCC OA V3.15 All versions , SIMATIC WinC… twitter.com/i/web/status/1… | 2022-12-13 17:24:42 |