CVE-2017-9939
published 2017-08-08CVE-2017-9939: A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPass…
PriorityP260critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.07%
79.2th percentile
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPass integrated server to bypass the authentication mechanism and perform administrative operations.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | sipass_integrated | <= 2.65 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →An unauthenticated attacker with network access to the SiPass integrated server can bypass authentication and perform administrative operations — monitor for unexpected administrative actions originating from unauthenticated or anomalous network sources targeting the SiPass integrated server. ↗
- →The vulnerability is remotely exploitable with low skill level required and no privileges or user interaction needed (CVSS PR:N/UI:N) — any network-level access attempt to the SiPass integrated server's administrative interface from untrusted hosts should be treated as suspicious. ↗
- ·All versions of SiPass integrated prior to V2.70 are affected; no known public exploits specifically target these vulnerabilities at time of advisory publication. ↗
- ·The advisory covers four CVEs (CVE-2017-9939 through CVE-2017-9942) affecting the same product; CVE-2017-9939 specifically covers the authentication bypass (CWE-287) with CVSS v3 score 9.8. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SiPass integrated
cisa_ics·2017-07-13
Siemens SiPass integrated
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SiPass integrated
Last RevisedJuly 13, 2017
Alert CodeICSA-17-194-01
## CVSS v3 9.8
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Siemens
Equipment: SiPass integrated
Vulnerabilities: Improper Authentication, Improper Privilege Management, Channel Accessible by Non-Endpoint, Storing Passwords in a Recoverable Format
## AFFECTED PRODUCTS
Siemens reports that the vulnerabilities affect the following SiPass integrated access control system:
- SiPass integrated: All versions prior to V2.70
## IMPACT
Successful exploitation of these vulnerabiliti
GHSA
GHSA-h9jq-9xw6-6ch6: A vulnerability was discovered in Siemens SiPass integrated (All versions before V2
ghsa_unreviewed·2022-05-13
CVE-2017-9939 [CRITICAL] CWE-287 GHSA-h9jq-9xw6-6ch6: A vulnerability was discovered in Siemens SiPass integrated (All versions before V2
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPass integrated server to bypass the authentication mechanism and perform administrative operations.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-08-08
Published