A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain credentials from the systems.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSiemens Sipass Integrated
APPSiemens≤ 2.65
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same product
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
CVE-2021-45046CRITICAL9.0⚠ KEVPL ✓same product
Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup
CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
CVE-2021-44523CRITICAL9.1PL ✓same product
Nieautoryzowany dostęp do bazy activity feed w Siemens SiPass/Siveillance
CVE-2021-44524CRITICAL9.8PL ✓same product
Auth Bypass w Siemens SiPass/Siveillance — nieautoryzowany dostęp do usługi uwierzytelniania