CVE-2022-43398
Estado: ModificadaAlta (8.8)—
A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50). Affected devices do not renew the session cookie after login/logout and also accept user defined session cookies. An attacker could overwrite the stored session cookie of a user. After the victim logged in, the attacker is given access to the user's account through the activated session.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.52%
- Percentil entre todas las CVEs puntuadas: 42
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-384
- CWE-384
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-43398",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "productcert@siemens.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "productcert@siemens.com",
"affectedData": [
{
"vendor": "Siemens",
"product": "POWER METER SICAM Q100",
"versions": [
{
"status": "affected",
"version": "All versions < V2.50"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "POWER METER SICAM Q100",
"versions": [
{
"status": "affected",
"version": "All versions < V2.50"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "POWER METER SICAM Q100",
"versions": [
{
"status": "affected",
"version": "All versions < V2.50"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "POWER METER SICAM Q100",
"versions": [
{
"status": "affected",
"version": "All versions < V2.50"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2022-11-08T11:15:11.940",
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-570294.pdf",
"tags": [
"Mitigation",
"Patch",
"Vendor Advisory"
],
"source": "productcert@siemens.com"
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-887249.pdf",
"source": "productcert@siemens.com"
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-570294.pdf",
"tags": [
"Mitigation",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-887249.pdf",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "productcert@siemens.com",
"description": [
{
"lang": "en",
"value": "CWE-384"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-384"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50). Affected devices do not renew the session cookie after login/logout and also accept user defined session cookies. An attacker could overwrite the stored session cookie of a user. After the victim logged in, the attacker is given access to the user's account through the activated session."
},
{
"lang": "es",
"value": "Se ha identificado una vulnerabilidad en la familia POWER METER SICAM Q200 (Todas las versiones < V2.70). Los dispositivos afectados no renuevan la cookie de sesión después de iniciar/cerrar sesión y también aceptan cookies de sesión definidas por el usuario. Un atacante podría sobrescribir la cookie de sesión almacenada de un usuario. Después de que la víctima inicia sesión, el atacante obtiene acceso a la cuenta del usuario a través de la sesión activada."
}
],
"lastModified": "2026-06-17T05:06:26.163",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:7kg9501-0aa01-2aa1_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "821380FC-8F3A-4437-94FF-FB95D9F187D0",
"versionEndExcluding": "2.50"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:7kg9501-0aa01-2aa1:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "275E9296-AACA-4F3B-B8FA-D52A59E729DE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:7kg9501-0aa31-2aa1_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AEE155DF-AB9B-4A85-A845-AF1B51B05833",
"versionEndExcluding": "2.50"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:7kg9501-0aa31-2aa1:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DC260D4F-53BD-433C-AE8F-FA2FA47BC921"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "productcert@siemens.com"
}