CVE-2022-40177 Details
Description
A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). Endpoints of the “Operation” web application that interpret and execute Axon language queries allow file read access to the device file system with root privileges. By supplying specific I/O related Axon queries, a remote low-privileged attacker can read sensitive files on the device.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-360783.pdf | CVE | PatchVendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-360783.pdf | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| siemens desigo pxm30-1 firmware | < 02.20.126.11-41 |
CPE
Remediation
| |
| siemens desigo pxm30-1 | All versions |
CPE
Remediation
| |
| siemens desigo pxm30.e firmware | < 02.20.126.11-41 |
CPE
Remediation
| |
| siemens desigo pxm30.e | All versions |
CPE
Remediation
| |
| siemens desigo pxm40-1 firmware | < 02.20.126.11-41 |
CPE
Remediation
| |
| siemens desigo pxm40-1 | All versions |
CPE
Remediation
| |
| siemens desigo pxm40.e firmware | < 02.20.126.11-41 |
CPE
Remediation
| |
| siemens desigo pxm40.e | All versions |
CPE
Remediation
| |
| siemens desigo pxm50-1 firmware | < 02.20.126.11-41 |
CPE
Remediation
| |
| siemens desigo pxm50-1 | All versions |
CPE
Remediation
| |
| siemens desigo pxm50.e firmware | < 02.20.126.11-41 |
CPE
Remediation
| |
| siemens desigo pxm50.e | All versions |
CPE
Remediation
| |
| siemens pxg3.w100-1 firmware | < 02.20.126.11-37 |
CPE
Remediation
| |
| siemens pxg3.w100-1 | All versions |
CPE
Remediation
| |
| siemens pxg3.w100-2 firmware | < 02.20.126.11-41 |
CPE
Remediation
| |
| siemens pxg3.w100-2 | All versions |
CPE
Remediation
| |
| siemens pxg3.w200-1 firmware | < 02.20.126.11-37 |
CPE
Remediation
| |
| siemens pxg3.w200-1 | All versions |
CPE
Remediation
| |
| siemens pxg3.w200-2 firmware | < 02.20.126.11-41 |
CPE
Remediation
| |
| siemens pxg3.w200-2 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 12, 2022 | Initial Analysis | [email protected] |