CVE-2025-40773: Medium severity SiPass SiPass integrated vulnerability
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side checks, allowing an attacker to execute a specific API request. Successful exploitation allows an attacker to potentially manipulate data belonging to other users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40773?
CVE-2025-40773 has been classified as a critical severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-40773?
To mitigate CVE-2025-40773, upgrade the SiPass integrated software to version 3.0 or later.
What type of vulnerability is CVE-2025-40773?
CVE-2025-40773 is a broken access control vulnerability affecting SiPass integrated applications.
Who is affected by CVE-2025-40773?
Organizations using SiPass integrated versions prior to 3.0 are affected by CVE-2025-40773.
Can CVE-2025-40773 be exploited remotely?
Yes, CVE-2025-40773 can be exploited remotely due to insufficient server-side authorization checks.