// For flags

CVE-2021-44523

 

Severity Score

9.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal activity feed database. This could allow an unauthenticated remote attacker to read, modify or delete activity feed entries.

Se ha identificado una vulnerabilidad en SiPass integrated versiones V2.76 (Todas las versiones), SiPass integrated versiones V2.80 (Todas las versiones), SiPass integrated versiones V2.85 (Todas las versiones), Siveillance Identity versiones V1.5 (Todas las versiones), Siveillance Identity versiones V1.6 (Todas las versiones anteriores a V1.6.284.0). Las aplicaciones afectadas no limitan suficientemente el acceso a la base de datos de alimentación de actividad interna. Esto podría permitir a un atacante remoto no autenticado leer, modificar o eliminar entradas de alimentación de actividad

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-12-02 CVE Reserved
  • 2021-12-14 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-29 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-668: Exposure of Resource to Wrong Sphere
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
Sipass Integrated
Search vendor "Siemens" for product "Sipass Integrated"
2.76
Search vendor "Siemens" for product "Sipass Integrated" and version "2.76"
-
Affected
Siemens
Search vendor "Siemens"
Sipass Integrated
Search vendor "Siemens" for product "Sipass Integrated"
2.76
Search vendor "Siemens" for product "Sipass Integrated" and version "2.76"
sp1
Affected
Siemens
Search vendor "Siemens"
Sipass Integrated
Search vendor "Siemens" for product "Sipass Integrated"
2.80
Search vendor "Siemens" for product "Sipass Integrated" and version "2.80"
-
Affected
Siemens
Search vendor "Siemens"
Sipass Integrated
Search vendor "Siemens" for product "Sipass Integrated"
2.85
Search vendor "Siemens" for product "Sipass Integrated" and version "2.85"
-
Affected
Siemens
Search vendor "Siemens"
Siveillance Identity
Search vendor "Siemens" for product "Siveillance Identity"
>= 1.6 <= 1.6.280.0
Search vendor "Siemens" for product "Siveillance Identity" and version " >= 1.6 <= 1.6.280.0"
-
Affected
Siemens
Search vendor "Siemens"
Siveillance Identity
Search vendor "Siemens" for product "Siveillance Identity"
1.5
Search vendor "Siemens" for product "Siveillance Identity" and version "1.5"
-
Affected