CVE-2017-9941
published 2017-08-08CVE-2017-9941: A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker in a Man-in-the-Middle position between…
PriorityP336high7.4CVSS 3.0
AVNACHPRNUINSUCHIHAN
EPSS
0.95%
57.0th percentile
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker in a Man-in-the-Middle position between the SiPass integrated server and SiPass integrated clients to read or modify the network communication.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | sipass_integrated | <= 2.65 | — |
CVSS provenance
nvdv3.07.4HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SiPass integrated
cisa_ics·2017-07-13
Siemens SiPass integrated
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SiPass integrated
Last RevisedJuly 13, 2017
Alert CodeICSA-17-194-01
## CVSS v3 9.8
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Siemens
Equipment: SiPass integrated
Vulnerabilities: Improper Authentication, Improper Privilege Management, Channel Accessible by Non-Endpoint, Storing Passwords in a Recoverable Format
## AFFECTED PRODUCTS
Siemens reports that the vulnerabilities affect the following SiPass integrated access control system:
- SiPass integrated: All versions prior to V2.70
## IMPACT
Successful exploitation of these vulnerabiliti
GHSA
GHSA-whwx-j639-prvw: A vulnerability was discovered in Siemens SiPass integrated (All versions before V2
ghsa_unreviewed·2022-05-13
CVE-2017-9941 [HIGH] CWE-300 GHSA-whwx-j639-prvw: A vulnerability was discovered in Siemens SiPass integrated (All versions before V2
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker in a Man-in-the-Middle position between the SiPass integrated server and SiPass integrated clients to read or modify the network communication.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-08-08
Published