The vendor explicitly identifies these products as affected by this CVE.
- Desigo DXR2
- Desigo PXC3
- Desigo PXC4
- Desigo PXC5
- Summary
- The login functionality of the application does not employ any countermeasures against Password Spraying attacks or Credential Stuffing attacks. An attacker could obtain a list of valid usernames on the device by exploiting the issue and then perform a precise Password Spraying or Credential Stuffing attack in order to obtain access to at least one account.
- Remediation
- Update to V01.21.142.5-22 or later version. Please contact your local Siemens office for additional support in obtaining the update.
