VDB

SSA-570294

SSA-570294 PUBLISHED CVSS 9.899999618530273 CRITICAL

Affected devices do not renew the session cookie after login/logout and also accept user defined session cookies. An attacker could overwrite the stored session cookie of a user. After the victim logged in, the attacker is given access to the user's account through the activated session.

Risk Scores

CVSS 3.1
9.899999618530273
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
SiemensPOWER METER SICAM Q100 (7KG9501-0AA01-0AA1)
SiemensPOWER METER SICAM Q100 (7KG9501-0AA31-2AA1)
SiemensPOWER METER SICAM Q100 (7KG9501-0AA31-0AA1)
SiemensPOWER METER SICAM Q100 (7KG9501-0AA01-2AA1)

Timeline

  • Nov 8, 2022 CVE Published
  • Jan 9, 2024 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›