A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile server component of affected applications improperly handles the log in for Active Directory accounts that are part of Administrators group. This could allow an unauthenticated remote attacker to access the application without a valid account.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSiemens Siveillance Video Mobile Server
APPSiemens< 22.2a\(80\)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
Related vulnerabilities
CVE-2026-0300CRITICAL9.3⚠ KEVPL ✓same vendor
Buffer overflow RCE z uprawnieniami root w PAN-OS Captive Portal
CVE-2026-24858CRITICAL9.8⚠ KEVPL ✓same vendor
Fortinet – Auth Bypass przez FortiCloud SSO w wielu produktach
CVE-2025-59718CRITICAL9.8⚠ KEVPL ✓same vendor
Fortinet FortiOS/FortiProxy/FortiSwitchManager — Auth Bypass przez SAML
CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same vendor
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
CVE-2021-45046CRITICAL9.0⚠ KEVPL ✓same vendor
Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup