The vendor explicitly identifies these products as affected by this CVE.
- Desigo PXM30-1
- Desigo PXM30.E
- Desigo PXM40-1
- Desigo PXM40.E
- Desigo PXM50-1
- Desigo PXM50.E
- PXG3.W100-1
- PXG3.W100-2
- PXG3.W200-1
- PXG3.W200-2
- Summary
- Endpoints of the “Operation” web application that interpret and execute Axon language queries allow file read access to the device file system with root privileges. By supplying specific I/O related Axon queries, a remote low-privileged attacker can read sensitive files on the device.
- Remediation
- Update to V02.20.126.11-41 or later version. Please contact your local Siemens office for additional support in obtaining the update.
