cbcvebase.
CVE-2017-9939
published 2017-08-08

CVE-2017-9939: A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPass…

PriorityP260critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.07%
79.2th percentile
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPass integrated server to bypass the authentication mechanism and perform administrative operations.

Affected

1 ranges
VendorProductVersion rangeFixed in
siemenssipass_integrated<= 2.65

Detection & IOCsextracted from sources · hover to see the quote

  • An unauthenticated attacker with network access to the SiPass integrated server can bypass authentication and perform administrative operations — monitor for unexpected administrative actions originating from unauthenticated or anomalous network sources targeting the SiPass integrated server.
  • The vulnerability is remotely exploitable with low skill level required and no privileges or user interaction needed (CVSS PR:N/UI:N) — any network-level access attempt to the SiPass integrated server's administrative interface from untrusted hosts should be treated as suspicious.
  • ·All versions of SiPass integrated prior to V2.70 are affected; no known public exploits specifically target these vulnerabilities at time of advisory publication.
  • ·The advisory covers four CVEs (CVE-2017-9939 through CVE-2017-9942) affecting the same product; CVE-2017-9939 specifically covers the authentication bypass (CWE-287) with CVSS v3 score 9.8.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.