CRITICAL🇵🇱 Wersja polska

CVE-2021-44524

CVSS 9.8v3.1pub. 2021-12-14upd. 2024-11-21

A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal user authentication service. This could allow an unauthenticated remote attacker to trigger several actions on behalf of valid user accounts.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Siemens Sipass Integrated

    APP
    Siemens
    2.762.802.85
  • Siemens Siveillance Identity

    APP
    Siemens
    1.51.6 – 1.6.284.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same product

Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+

CVE-2021-45046CRITICAL9.0⚠ KEVPL ✓same product

Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup

CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product

Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup

CVE-2021-44523CRITICAL9.1PL ✓same product

Nieautoryzowany dostęp do bazy activity feed w Siemens SiPass/Siveillance

CVE-2017-9939CRITICAL9.8PL ✓same product

Pominięcie uwierzytelnienia w Siemens SiPass Integrated — dostęp administracyjny