CVE-2021-44523

A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal activity feed database. This could allow an unauthenticated remote attacker to read, modify or delete activity feed entries.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:sipass_integrated:2.76:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sipass_integrated:2.76:sp1:*:*:*:*:*:*
cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:*
cpe:2.3:a:siemens:siveillance_identity:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:*

History

17 Dec 2021, 13:22

Type Values Removed Values Added
CPE cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sipass_integrated:2.76:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sipass_integrated:2.76:sp1:*:*:*:*:*:*
cpe:2.3:a:siemens:siveillance_identity:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.4
v3 : 9.1
References (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-160202.pdf - (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-160202.pdf - Vendor Advisory
References (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-463116.pdf - (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-463116.pdf - Vendor Advisory

14 Dec 2021, 13:15

Type Values Removed Values Added
Summary A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal activity feed database. This could allow an unauthenticated remote attacker to read, modify or delete activity feed entries. A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal activity feed database. This could allow an unauthenticated remote attacker to read, modify or delete activity feed entries.

14 Dec 2021, 12:28

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-14 12:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-44523

Mitre link : CVE-2021-44523

CVE.ORG link : CVE-2021-44523


JSON object : View

Products Affected

siemens

  • siveillance_identity
  • sipass_integrated
CWE
CWE-668

Exposure of Resource to Wrong Sphere