Headline
CVE-2022-24042
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application returns an AuthToken that does not expire at the defined auto logoff delay timeout. An attacker could be able to capture this token and re-use old session credentials or session IDs for authorization.
%PDF-1.5 %���� 1 0 obj << /D [2 0 R /XYZ 70.866 771.024 null] >> endobj 3 0 obj << /D [2 0 R /XYZ 70.866 630.026 null] >> endobj 4 0 obj << /D [2 0 R /XYZ 70.866 569.947 null] >> endobj 5 0 obj << /D [2 0 R /XYZ 70.866 269.791 null] >> endobj 6 0 obj << /D [2 0 R /XYZ 70.866 210.707 null] >> endobj 7 0 obj << /D [8 0 R /XYZ 85.039 509.165 null] >> endobj 9 0 obj << /D [8 0 R /XYZ 70.866 236.749 null] >> endobj 10 0 obj << /S /GoTo /D [2 0 R /Fit] >> endobj 2 0 obj << /Contents 11 0 R /Type /Page /Resources 12 0 R /Parent 13 0 R /Annots [14 0 R 15 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 14 0 obj << /A << /S /GoTo /D (section*.2) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [386.143 227.524 524.579 239.061] >> endobj 15 0 obj << /A << /S /GoTo /D (section*.4) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [147.498 209.711 309.548 221.128] >> endobj 12 0 obj << /ProcSet [/PDF /Text] /Font << /F48 16 0 R /F45 17 0 R >> >> endobj 11 0 obj << /Filter /FlateDecode /Length 2095 >> stream x��ZKs�F��W�V��y� ��"�.’�cEJI�Ɂ"!�|��Ϳ߯1I�k������7M��!`����g�z�tG�&��EΘ��q�� Ƴ�S8J�E���ºp�Lw����0�����c�]�(YX��b?�,��Y�v����z�����Ϯ�g�q�~@GV�`�8��fx�c�"��K>s(-#�$��`t��3V(U~Vx�zV��9��ө(�j�ҟ���be���8��4:b�ظ�� q�#.�ln#����G�����’���’^U���g�z��e\GBt�:2F6/��t��G ��"=13���H&wۄܒ����+�HZ�K��DZ�.,bx�s���\������p7_&��]:O�4��5�Є�^&��\�N&�"r6nӄ�)wb�tY\1��>�+����B��� ���A�����6}X5o��ס+��Q;�H�V����)�H���^4_��*%M��t��t��.��p^�|��5�
Related news
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application returns an AuthToken that does not expire at the defined auto logoff delay timeout. An attacker could be able to capture this token and re-use old session credentials or session IDs for authorization.