« Volver al listado

CVE-2022-40177

Estado: ModificadaMedia (5.7)—

A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41).

Leer descripción completaMostrar menos

Endpoints of the “Operation” web application that interpret and execute Axon language queries allow file read access to the device file system with root privileges. By supplying specific I/O related Axon queries, a remote low-privileged attacker can read sensitive files on the device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (10)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-40177",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.7,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "productcert@siemens.com",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "Desigo PXM30-1",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V02.20.126.11-41"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Desigo PXM30.E",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V02.20.126.11-41"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Desigo PXM40-1",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V02.20.126.11-41"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Desigo PXM40.E",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V02.20.126.11-41"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Desigo PXM50-1",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V02.20.126.11-41"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Desigo PXM50.E",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V02.20.126.11-41"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "PXG3.W100-1",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V02.20.126.11-37"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "PXG3.W100-2",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V02.20.126.11-41"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "PXG3.W200-1",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V02.20.126.11-37"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "PXG3.W200-2",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V02.20.126.11-41"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-10-11T11:15:10.533",
  "references": [
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-360783.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "productcert@siemens.com"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-360783.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "productcert@siemens.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). Endpoints of the “Operation” web application that interpret and execute Axon language queries allow file read access to the device file system with root privileges. By supplying specific I/O related Axon queries, a remote low-privileged attacker can read sensitive files on the device."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una vulnerabilidad en Desigo PXM30-1 (Todas las versiones anteriores a V02.20.126.11-41), Desigo PXM30.E (Todas las versiones anteriores a V02.20.126.11-41), Desigo PXM40-1 (Todas las versiones anteriores a V02.20.126.11-41), Desigo PXM40.E (Todas las versiones anteriores a V02.20.126.11-41), Desigo PXM50-1 (Todas las versiones anteriores a V02. 20.126.11-41), Desigo PXM50.E (Todas las versiones anteriores a V02.20.126.11-41), PXG3.W100-1 (Todas las versiones anteriores a V02.20.126.11-37), PXG3.W100-2 (Todas las versiones anteriores a V02.20.126.11-41), PXG3.W200-1 (Todas las versiones anteriores a V02.20.126.11-37), PXG3.W200-2 (Todas las versiones anteriores a V02.20.126.11-41). Los endpoints de la aplicación web \"Operación\" que interpretan y ejecutan consultas en lenguaje Axon permiten el acceso de lectura de archivos al sistema de archivos del dispositivo privilegiado de root. Al suministrar consultas específicas de Axon relacionadas con la E/S, un atacante remoto poco privilegiado puede leer archivos confidenciales en el dispositivo"
    }
  ],
  "lastModified": "2026-06-17T05:01:03.233",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:desigo_pxm30-1_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA01FD1D-3B4F-44CB-85D5-D88190B264A3",
              "versionEndExcluding": "02.20.126.11-41"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:desigo_pxm30-1:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "837673FE-DBBB-496A-8A6F-0C53BC5F2EAD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:desigo_pxm30.e_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "863709BC-3A74-49E5-80F3-7E0227BD3403",
              "versionEndExcluding": "02.20.126.11-41"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:desigo_pxm30.e:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "60A4FA01-FD7F-451F-8BEB-2BF01A2DF9B6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:desigo_pxm40-1_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B63901A-F3B7-4232-973F-7E162608FEA0",
              "versionEndExcluding": "02.20.126.11-41"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:desigo_pxm40-1:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DA0AA432-2A2C-4A03-86C5-560592562653"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:desigo_pxm40.e_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87180ACC-C1ED-4F20-9460-1AFD53D28CA2",
              "versionEndExcluding": "02.20.126.11-41"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:desigo_pxm40.e:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A0517B82-90A9-4A0F-8B57-70F2A679DC95"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:desigo_pxm50-1_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E14C8DD3-9FA4-497F-9F9F-235C8D2DEFA5",
              "versionEndExcluding": "02.20.126.11-41"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:desigo_pxm50-1:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0BBE6D5C-A3AF-4191-A283-805B834D9475"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:desigo_pxm50.e_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "663CD9F1-2455-4B73-9081-4FA3A1FD46D3",
              "versionEndExcluding": "02.20.126.11-41"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:desigo_pxm50.e:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CECB9D5A-2654-4DE5-91CF-59DB43776FBC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:pxg3.w100-1_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5C23DFD-0362-4554-9761-3D684796C0DC",
              "versionEndExcluding": "02.20.126.11-37"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:pxg3.w100-1:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C9805AE4-F07B-45F6-A1DD-53544E8AE681"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:pxg3.w100-2_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01049ABF-EAD0-4B8D-B54C-3424B435635A",
              "versionEndExcluding": "02.20.126.11-41"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:pxg3.w100-2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4924B858-7BB5-464F-B6E5-133B987FF122"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:pxg3.w200-1_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5FB1F863-2762-4839-A601-248BC0F8B6D5",
              "versionEndExcluding": "02.20.126.11-37"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:pxg3.w200-1:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2CCA20E3-2425-4004-801F-46898ACDA2CD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:pxg3.w200-2_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0903929A-B47C-4E75-A6B6-1DB4B118F64C",
              "versionEndExcluding": "02.20.126.11-41"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:pxg3.w200-2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "14AE1458-8F82-4F6D-987D-4F22AF5E8056"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "productcert@siemens.com"
}