Siemens SiPass integrated
cpe:2.3:a:siemens:sipass_integrated:*:*:*:*:*:*:*
- < V3.0
A broken access control vulnerability has been identified in Siemens SiPass Integrated, all versions prior to 3.0. The vulnerability arises from an inadequate authorization mechanism that fails to implement sufficient server-side checks. This flaw allows an attacker to execute specific API requests, potentially leading to unauthorized manipulation of data belonging to other users.
Exploitation of this vulnerability could result in unauthorized data manipulation, affecting other users' information within the application.
Users are advised to update to SiPass Integrated version 3.0 or later. For more information, visit the Siemens Support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.