CVE-2017-9940: High severity sipass integrated vulnerability
Published Aug 8, 2017
·Updated
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-privileged user account to read or write files on the file system of the SiPass integrated server over the network.
Affected Software
1 affected component
Siemens SiPass integrated<=2.65
Event History
Aug 8, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-9940?
CVE-2017-9940 has a medium severity rating due to the potential for unauthorized file access by low-privileged users.
2
How do I fix CVE-2017-9940?
To fix CVE-2017-9940, upgrade Siemens SiPass integrated to version 2.70 or later.
3
Who is affected by CVE-2017-9940?
All versions of Siemens SiPass integrated before V2.70 are affected by CVE-2017-9940.
4
What can an attacker do with CVE-2017-9940?
An attacker can read or write files on the file system of the SiPass integrated server over the network.
5
Is CVE-2017-9940 related to user account privileges?
Yes, CVE-2017-9940 allows an attacker with low-privileged user access to exploit the vulnerability.