Vulnerability Description
The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Simatic S7-1500 Software Controller | - |
| Siemens | Simatic S7-Plcsim Advanced | - |
| Siemens | Simatic Wincc Runtime | - |
| Siemens | 6Es7154-8Fb01-0Ab0 Firmware | < 3.2.19 |
| Siemens | 6Es7154-8Fb01-0Ab0 | - |
| Siemens | 6Es7154-8Ab01-0Ab0 Firmware | < 3.2.19 |
| Siemens | 6Es7154-8Ab01-0Ab0 | - |
| Siemens | 6Es7154-8Fx00-0Ab0 Firmware | < 3.2.19 |
| Siemens | 6Es7154-8Fx00-0Ab0 | - |
| Siemens | 6Es7151-8Ab01-0Ab0 Firmware | < 3.2.19 |
| Siemens | 6Es7151-8Ab01-0Ab0 | - |
| Siemens | 6Es7151-8Fb01-0Ab0 Firmware | < 3.2.19 |
| Siemens | 6Es7151-8Fb01-0Ab0 | - |
| Siemens | 6Es7314-6Eh04-0Ab0 Firmware | < 3.3.19 |
| Siemens | 6Es7314-6Eh04-0Ab0 | - |
| Siemens | 6Es7315-2Eh14-0Ab0 Firmware | < 3.2.19 |
| Siemens | 6Es7315-2Eh14-0Ab0 | - |
| Siemens | 6Es7315-2Fj14-0Ab0 Firmware | < 3.2.19 |
| Siemens | 6Es7315-2Fj14-0Ab0 | - |
| Siemens | 6Es7315-7Tj10-0Ab0 Firmware | < 3.2.19 |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-478960.pdfPatchVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-478960.pdfPatchVendor Advisory
FAQ
What is CVE-2022-30694?
CVE-2022-30694 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cros...
How severe is CVE-2022-30694?
CVE-2022-30694 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-30694?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Simatic S7-1500 Software Controller, Siemens Simatic S7-Plcsim Advanced, Siemens Simatic Wincc Runtime, Siemens 6Es7154-8Fb01-0Ab0 Firmware, Siemens 6Es7154-8Fb01-0Ab0.