HIGH
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0)
Published Dec 14, 2021
7.5
HIGHCVSS 3.1
EPSS 1.36%
Description
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal message broker system. This could allow an unauthenticated remote attacker to subscribe to arbitrary message queues.
Affected products
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versions < V1.6.284.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Siemens | SiPass integrated V2.76 | n/a |
| ||||||
| Siemens | SiPass integrated V2.80 | n/a |
| ||||||
| Siemens | SiPass integrated V2.85 | n/a |
| ||||||
| Siemens | Siveillance Identity V1.5 | n/a |
| ||||||
| Siemens | Siveillance Identity V1.6 | n/a |
|
OR
- 2.76
- 2.76
- 2.80
- 2.85
- ≥ 1.6 · ≤ 1.6.280.0
- 1.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://cert-portal.siemens.com/productcert/pdf/ssa-160202.pdf x_refsource_MISCVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-463116.pdf x_refsource_MISCVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-31354 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-160202.pdf | x_refsource_MISCVendor Advisory | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-463116.pdf | x_refsource_MISCVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-31354 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner siemens
Published Dec 14, 2021
Updated Aug 4, 2024
Reserved Dec 2, 2021
Link CVE-2021-44522
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-31354 Assigner siemens
Published Dec 14, 2021
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2021-31354