First published: Tue Dec 14 2021(Updated: )
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal message broker system. This could allow an unauthenticated remote attacker to subscribe to arbitrary message queues.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SiPass integrated | =2.76 | |
Siemens SiPass integrated | =2.76-sp1 | |
Siemens SiPass integrated | =2.80 | |
Siemens SiPass integrated | =2.85 | |
Siemens Siveillance Identity | >=1.6<=1.6.280.0 | |
Siemens Siveillance Identity | =1.5 | |
=2.76 | ||
=2.76-sp1 | ||
=2.80 | ||
=2.85 | ||
>=1.6<=1.6.280.0 | ||
=1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-44522 is high.
The affected software of CVE-2021-44522 is Siemens SiPass integrated V2.76, Siemens SiPass integrated V2.80, Siemens SiPass integrated V2.85, Siveillance Identity V1.5, and Siveillance Identity V1.6 (versions < V1.6.284.0).
To fix the vulnerability in CVE-2021-44522, update to the latest version of SiPass integrated or Siveillance Identity software.
More information about CVE-2021-44522 can be found in the following references: [Reference 1](https://cert-portal.siemens.com/productcert/pdf/ssa-160202.pdf), [Reference 2](https://cert-portal.siemens.com/productcert/pdf/ssa-463116.pdf).
The CWE ID of CVE-2021-44522 is 668.