Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43398


A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50). Affected devices do not renew the session cookie after login/logout and also accept user defined session cookies. An attacker could overwrite the stored session cookie of a user. After the victim logged in, the attacker is given access to the user's account through the activated session.


Published

2022-11-08T11:15:11.940

Last Modified

2024-11-21T07:26:24.183

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-384
  • Type: Primary
    CWE-384

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens 7kg9501-0aa01-2aa1_firmware < 2.50 Yes
Hardware siemens 7kg9501-0aa01-2aa1 - No
Operating System siemens 7kg9501-0aa31-2aa1_firmware < 2.50 Yes
Hardware siemens 7kg9501-0aa31-2aa1 - No

References