The vendor explicitly identifies these products as affected by this CVE.
- Desigo PXM30-1
- Desigo PXM30.E
- Desigo PXM40-1
- Desigo PXM40.E
- Desigo PXM50-1
- Desigo PXM50.E
- PXG3.W100-1
- PXG3.W100-2
- PXG3.W200-1
- PXG3.W200-2
- Summary
- A Cross-Site Request Forgery exists in the “Import Files“ functionality of the “Operation” web application due to the missing validation of anti-CSRF tokens or other origin checks. A remote unauthenticated attacker can upload and enable permanent arbitrary JavaScript code into the device just by convincing a victim to visit a specifically crafted webpage while logged-in to the device web application.
- Remediation
- Update to V02.20.126.11-41 or later version. Please contact your local Siemens office for additional support in obtaining the update.
