« Volver al listado

Siemens

Siemens Sipass Integrated: vulnerabilidades y CVE

Siemens Sipass Integrated tiene 16 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 6 son críticas y 3 figuran en el catálogo de explotación activa de CISA.

CVE16
Últimos 12 meses3
Críticas6
Explotadas activamente3

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-45046Crítica (9)100%⚠ Explotación activa14 dic 2021
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the…
CVE-2022-22965Crítica (9.8)100%⚠ Explotación activa1 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the…
CVE-2021-44228Crítica (10)100%⚠ Explotación activa10 dic 2021
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-40774Media (6.7)0.14%—14 oct 2025
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user passwords encrypted in its database. Decryption keys are accessible to users with administrative…
CVE-2025-40773Media (5.1)0.20%—14 oct 2025
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side…
CVE-2025-40772Alta (7)0.32%—14 oct 2025
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnerable to stored Cross-Site Scripting (XSS), allowing an attacker to inject malicious code that can be…
CVE-2022-31812Alta (8.7)0.62%—23 may 2025
A vulnerability has been identified in SiPass integrated (All versions < V2.95.3.18). Affected server applications contain an out of bounds read past the end of an allocated buffer while checking the integrity of…
CVE-2022-31810Alta (7.5)0.88%—11 jul 2023
A vulnerability has been identified in SiPass integrated (All versions < V2.90.3.8). Affected server applications improperly check the size of data packets received for the configuration client login, causing a…
CVE-2022-22965Crítica (9.8)100%⚠ Explotación activa1 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the…
CVE-2021-45046Crítica (9)100%⚠ Explotación activa14 dic 2021
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the…
CVE-2021-44524Crítica (9.8)1.6%—14 dic 2021
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance…
CVE-2021-44523Crítica (9.1)1.4%—14 dic 2021
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance…
CVE-2021-44522Alta (7.5)1.4%—14 dic 2021
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance…
CVE-2021-44228Crítica (10)100%⚠ Explotación activa10 dic 2021
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other…
CVE-2017-9942Alta (7.8)0.27%—8 ago 2017
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain…
CVE-2017-9941Alta (7.4)0.95%—8 ago 2017
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker in a Man-in-the-Middle position between the SiPass integrated server and SiPass integrated clients to…
CVE-2017-9940Alta (8.1)0.86%—8 ago 2017
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-privileged user account to read or write files on the file system of the SiPass…
CVE-2017-9939Crítica (9.8)2.1%—8 ago 2017
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPass integrated server to bypass the authentication mechanism and perform…
CVE-2012-5409Alta (10)16%—1 nov 2012
AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory…

Otros productos de Siemens