CVE-2022-33139 Client-side Authentication

Discussion about security topics in WinCC OA!
Search

Post Reply
4 posts • Page 1 of 1
heinz.romann
Posts: 2
Joined: Mon Feb 06, 2012 8:42 am

CVE-2022-33139 Client-side Authentication

Post by heinz.romann »

The Siemens Security Advisory recommends using server-side authentication as a solution to this problem. We still want to use client-side authentication so that we can use SSO (SingleSignOn). Will this issue be fixed with a patch?

User avatar
leoknipp
Posts: 2846
Joined: Tue Aug 24, 2010 7:28 pm

Re: CVE-2022-33139 Client-side Authentication

Post by leoknipp »

In the linked pdf document it is described which solutions are available to avoid this issue:
https://cert-portal.siemens.com/product ... 111512.pdf

If you have further questions please get in contact with your common WinCC OA support and/or the company responsible for your project.

Best Regards
Leopold Knipp
Senior Support Specialist

AbtSIAL
Posts: 1
Joined: Wed Feb 23, 2011 9:11 am

Re: CVE-2022-33139 Client-side Authentication

Post by AbtSIAL »

Yes we are aware about this "solution". But we need a solution for SSO (SingleSignOn), which works only with client-side authentication.

User avatar
leoknipp
Posts: 2846
Joined: Tue Aug 24, 2010 7:28 pm

Re: CVE-2022-33139 Client-side Authentication

Post by leoknipp »

Please refer also to the following article
https://support.industry.siemens.com/cs ... 0&lc=en-US

If you have further questions please get in contact with your common WinCC OA support and/or the system integrator responsible for your project.

Best Regards
Leopold Knipp
Senior Support Specialist

Post Reply
4 posts • Page 1 of 1