Man-in-the-Middle Vulnerability in Siemens SiPass Integrated System
CVE-2017-9941

7.4HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
8 August 2017

Summary

A security vulnerability has been identified in Siemens SiPass integrated systems, specifically affecting all versions prior to V2.70. This flaw could enable an attacker positioned between the SiPass integrated server and the client systems to intercept and manipulate the network communication. Such unauthorized access poses significant risks, potentially allowing for data compromise and unauthorized actions within the affected systems. Users of SiPass integrated are urged to upgrade to the latest version to mitigate these risks.

Affected Version(s)

SiPass integrated All before V2.70 SiPass integrated All versions before V2.70

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.