CVE-2022-30694
published 2022-11-08CVE-2022-30694: The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the…
PriorityP413low3.5CVSS 3.1
AVNACLPRLUIRSUCLINAN
EPSS
0.29%
21.3th percentile
The login endpoint /FormLogin in affected web services does not apply proper origin checking.
This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.
Affected
144 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | 6ag1151-8ab01-7ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6ag1151-8fb01-2ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6ag1314-6eh04-7ab0_firmware | < 3.3.19 | 3.3.19 |
| siemens | 6ag1315-2eh14-7ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6ag1315-2fj14-2ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6ag1317-2ek14-7ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6ag1317-2fk14-2ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6es7151-8ab01-0ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6es7151-8fb01-0ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6es7154-8ab01-0ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6es7154-8fb01-0ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6es7154-8fx00-0ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6es7314-6eh04-0ab0_firmware | < 3.3.19 | 3.3.19 |
| siemens | 6es7315-2eh14-0ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6es7315-2fj14-0ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6es7315-7tj10-0ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6es7317-2ek14-0ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6es7317-2fk14-0ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6es7317-7tk10-0ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6es7317-7ul10-0ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6es7318-3el01-0ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | 6es7318-3fl01-0ab0_firmware | < 3.2.19 | 3.2.19 |
| siemens | simatic_drive_controller_cpu_1504d_tf | — | — |
| siemens | simatic_drive_controller_cpu_1507d_tf | — | — |
| siemens | simatic_et_200pro_im154-8_pn_dp_cpu | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4f6c-cjgm-c8qx: A vulnerability has been identified in SIMATIC Drive Controller family (All versions), SIMATIC ET 200S IM151-8 PN/DP CPU (All versions = V2
ghsa_unreviewed·2022-11-08
CVE-2022-30694 [LOW] CWE-352 GHSA-4f6c-cjgm-c8qx: A vulnerability has been identified in SIMATIC Drive Controller family (All versions), SIMATIC ET 200S IM151-8 PN/DP CPU (All versions = V2
A vulnerability has been identified in SIMATIC Drive Controller family (All versions), SIMATIC ET 200S IM151-8 PN/DP CPU (All versions = V2.1), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-1500 Software Controller (All versions), SIMATIC S7-300 CPU 314C-2 PN/DP (All versions < V3.3.19), SIMATIC S7-300 CPU 315-2 PN/DP (All versions < V3.2.19), SIMATIC S7-300 CPU 315F-2 PN/DP (All versions < V3.2.19), SIMATIC S7-300 CPU 315T-3 PN/DP (All versions < V3.2.19), SIMATIC S7-300 CPU 317-2 PN/DP (All versions < V3.2.19), SIMATIC S7-300 CPU 317F-2 PN/DP (All versions < V3.2.19), SIMATIC S7-300 CPU 317T-3 PN/DP (All versions < V3.2.19), SIMATIC S7-300 CPU 317TF-3 PN/DP (All versi
CISA ICS
Siemens Web Server Login Page of Industrial Controllers (Update A)
cisa_ics·2022-11-10
Siemens Web Server Login Page of Industrial Controllers (Update A)
ICS Advisory
##
Siemens Web Server Login Page of Industrial Controllers (Update A)
Last RevisedJanuary 13, 2023
Alert CodeICSA-22-314-02
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.5
- ATTENTION: Exploitable Remotely/low Attack Complexity
- Vendor: Siemens
- Equipment: SIMATIC Industrial Controllers and Software
- Vulnerability: Cross-Site Request Forgery (CSRF)
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled IC
No detection rules found.
No public exploits indexed.
2022-11-08
Published