A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow an authenticated attacker to impersonate other users of the system and perform (potentially administrative) actions on behalf of those users if the single sign-on feature ("Allow logon without password") is enabled.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSiemens Siport Mp
APPSiemens< 3.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
Related vulnerabilities
CVE-2019-19277MEDIUM6.5same product
A vulnerability has been identified in SIPORT MP (All versions < 3.1.4). Vulnerable versions of the device all...
CVE-2026-0300CRITICAL9.3⚠ KEVPL ✓same vendor
Buffer overflow RCE z uprawnieniami root w PAN-OS Captive Portal
CVE-2026-24858CRITICAL9.8⚠ KEVPL ✓same vendor
Fortinet – Auth Bypass przez FortiCloud SSO w wielu produktach
CVE-2025-59718CRITICAL9.8⚠ KEVPL ✓same vendor
Fortinet FortiOS/FortiProxy/FortiSwitchManager — Auth Bypass przez SAML
CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same vendor
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+