CVE-2021-44524
14.12.2021, 12:15
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal user authentication service. This could allow an unauthenticated remote attacker to trigger several actions on behalf of valid user accounts.Enginsight
Vendor | Product | Version |
---|---|---|
siemens | sipass_integrated | 2.76 |
siemens | sipass_integrated | 2.76:sp1 |
siemens | sipass_integrated | 2.80 |
siemens | sipass_integrated | 2.85 |
siemens | siveillance_identity | 1.6 ≤ 𝑥 ≤ 1.6.284.0 |
siemens | siveillance_identity | 1.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-668 - Exposure of Resource to Wrong SphereThe product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.