Siemens
Siemens Sipass Integrated: vulnerabilidades y CVE
Siemens Sipass Integrated tiene 16 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 6 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses3
Críticas6
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-45046 | Crítica (9) | 100% | ⚠ Explotación activa | 14 dic 2021 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the… |
| CVE-2022-22965 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 abr 2022 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the… |
| CVE-2021-44228 | Crítica (10) | 100% | ⚠ Explotación activa | 10 dic 2021 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-40774 | Media (6.7) | 0.14% | — | 14 oct 2025 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user passwords encrypted in its database. Decryption keys are accessible to users with administrative… |
| CVE-2025-40773 | Media (5.1) | 0.20% | — | 14 oct 2025 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side… |
| CVE-2025-40772 | Alta (7) | 0.32% | — | 14 oct 2025 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnerable to stored Cross-Site Scripting (XSS), allowing an attacker to inject malicious code that can be… |
| CVE-2022-31812 | Alta (8.7) | 0.62% | — | 23 may 2025 | A vulnerability has been identified in SiPass integrated (All versions < V2.95.3.18). Affected server applications contain an out of bounds read past the end of an allocated buffer while checking the integrity of… |
| CVE-2022-31810 | Alta (7.5) | 0.88% | — | 11 jul 2023 | A vulnerability has been identified in SiPass integrated (All versions < V2.90.3.8). Affected server applications improperly check the size of data packets received for the configuration client login, causing a… |
| CVE-2022-22965 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 abr 2022 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the… |
| CVE-2021-45046 | Crítica (9) | 100% | ⚠ Explotación activa | 14 dic 2021 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the… |
| CVE-2021-44524 | Crítica (9.8) | 1.6% | — | 14 dic 2021 | A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance… |
| CVE-2021-44523 | Crítica (9.1) | 1.4% | — | 14 dic 2021 | A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance… |
| CVE-2021-44522 | Alta (7.5) | 1.4% | — | 14 dic 2021 | A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance… |
| CVE-2021-44228 | Crítica (10) | 100% | ⚠ Explotación activa | 10 dic 2021 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other… |
| CVE-2017-9942 | Alta (7.8) | 0.27% | — | 8 ago 2017 | A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain… |
| CVE-2017-9941 | Alta (7.4) | 0.95% | — | 8 ago 2017 | A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker in a Man-in-the-Middle position between the SiPass integrated server and SiPass integrated clients to… |
| CVE-2017-9940 | Alta (8.1) | 0.86% | — | 8 ago 2017 | A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-privileged user account to read or write files on the file system of the SiPass… |
| CVE-2017-9939 | Crítica (9.8) | 2.1% | — | 8 ago 2017 | A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPass integrated server to bypass the authentication mechanism and perform… |
| CVE-2012-5409 | Alta (10) | 16% | — | 1 nov 2012 | AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory… |