CVE-2017-9942
published 2017-08-08CVE-2017-9942: A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated…
PriorityP335high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
19.4th percentile
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain credentials from the systems.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | sipass_integrated | <= 2.65 | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3877-qfcm-54mw: A vulnerability was discovered in Siemens SiPass integrated (All versions before V2
ghsa_unreviewed·2022-05-13
CVE-2017-9942 [HIGH] CWE-257 GHSA-3877-qfcm-54mw: A vulnerability was discovered in Siemens SiPass integrated (All versions before V2
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain credentials from the systems.
CISA ICS
Siemens SiPass integrated
cisa_ics·2017-07-13
Siemens SiPass integrated
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SiPass integrated
Last RevisedJuly 13, 2017
Alert CodeICSA-17-194-01
## CVSS v3 9.8
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Siemens
Equipment: SiPass integrated
Vulnerabilities: Improper Authentication, Improper Privilege Management, Channel Accessible by Non-Endpoint, Storing Passwords in a Recoverable Format
## AFFECTED PRODUCTS
Siemens reports that the vulnerabilities affect the following SiPass integrated access control system:
- SiPass integrated: All versions prior to V2.70
## IMPACT
Successful exploitation of these vulnerabiliti
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-08-08
Published