Privilege Escalation Vulnerability in SiPass Integrated Products by Siemens
CVE-2025-27493
9.3CRITICAL
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 11 March 2025
What is CVE-2025-27493?
A vulnerability in Siemens SiPass integrated AC5102 and ACC-AP systems allows authenticated local administrators to exploit improper input sanitization on the telnet command line interface. By injecting arbitrary commands, these administrators could execute operations with root privileges, potentially leading to unauthorized system changes and escalated access.
Affected Version(s)
SiPass integrated AC5102 (ACC-G2) 0
SiPass integrated ACC-AP 0