Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-44731


A vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions < V3.15 P038), SIMATIC WinCC OA V3.16 (All versions < V3.16 P035), SIMATIC WinCC OA V3.17 (All versions < V3.17 P024), SIMATIC WinCC OA V3.18 (All versions < V3.18 P014). The affected component allows to inject custom arguments to the Ultralight Client backend application under certain circumstances. This could allow an authenticated remote attacker to inject arbitrary parameters when starting the client via the web interface (e.g., open attacker chosen panels with the attacker's credentials or start a Ctrl script).


Published

2022-12-13T16:15:24.543

Last Modified

2024-11-21T07:28:23.160

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-88
  • Type: Secondary
    CWE-88

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens simatic_wincc_oa 3.15 Yes
Application siemens simatic_wincc_oa 3.16 Yes
Application siemens simatic_wincc_oa 3.17 Yes
Application siemens simatic_wincc_oa 3.18 Yes

References