CVE-2021-44524
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal user authentication service. This could allow an unauthenticated remote attacker to trigger several actions on behalf of valid user accounts.
Se ha identificado una vulnerabilidad en SiPass integrated versiones V2.76 (Todas las versiones), SiPass integrated versiones V2.80 (Todas las versiones), SiPass integrated versiones V2.85 (Todas las versiones), Siveillance Identity versiones V1.5 (Todas las versiones), Siveillance Identity versiones V1.6 (Todas las versiones anteriores a V1.6.284.0). Las aplicaciones afectadas no limitan suficientemente el acceso al servicio interno de autenticación de usuarios. Esto podría permitir a un atacante remoto no autenticado desencadenar varias acciones en nombre de cuentas de usuario válidas
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-12-02 CVE Reserved
- 2021-12-14 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
- CWE-668: Exposure of Resource to Wrong Sphere
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-160202.pdf | 2021-12-17 | |
https://cert-portal.siemens.com/productcert/pdf/ssa-463116.pdf | 2021-12-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Sipass Integrated Search vendor "Siemens" for product "Sipass Integrated" | 2.76 Search vendor "Siemens" for product "Sipass Integrated" and version "2.76" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Sipass Integrated Search vendor "Siemens" for product "Sipass Integrated" | 2.76 Search vendor "Siemens" for product "Sipass Integrated" and version "2.76" | sp1 |
Affected
| ||||||
Siemens Search vendor "Siemens" | Sipass Integrated Search vendor "Siemens" for product "Sipass Integrated" | 2.80 Search vendor "Siemens" for product "Sipass Integrated" and version "2.80" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Sipass Integrated Search vendor "Siemens" for product "Sipass Integrated" | 2.85 Search vendor "Siemens" for product "Sipass Integrated" and version "2.85" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Siveillance Identity Search vendor "Siemens" for product "Siveillance Identity" | >= 1.6 <= 1.6.284.0 Search vendor "Siemens" for product "Siveillance Identity" and version " >= 1.6 <= 1.6.284.0" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Siveillance Identity Search vendor "Siemens" for product "Siveillance Identity" | 1.5 Search vendor "Siemens" for product "Siveillance Identity" and version "1.5" | - |
Affected
|