news.mlab.sh
Back to the feed
vulnerability

Siemens gWAP

High
Summary

A remote code execution vulnerability has been identified in Siemens gWAP, stemming from a prototype pollution issue within the Axios HTTP client library. This vulnerability, exploitable through a ‘Gadget’ attack chain, could allow an attacker to execute arbitrary code and potentially compromise the system. Siemens has released version 3.1.1 to address this issue, and CISA recommends updating to the latest version and implementing network security best practices to mitigate the risk.

The vulnerability was discovered within the Axios HTTP client library, a component used by Siemens gWAP. Specifically, versions prior to 1.15.0 and 0.3.1 were susceptible to a ‘Gadget’ attack chain, which leverages prototype pollution to escalate vulnerabilities. This allows an attacker to inject malicious code into other third-party libraries, ultimately leading to remote code execution (RCE) or, in severe cases, bypassing security measures like AWS IMDSv2 for full cloud compromise. Siemens has released version 3.1.1 to patch this vulnerability, and recommends immediate updates to all affected systems.

Read the full article at CISA Advisories