Home
HIGH: 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
3.0.48
affected
Description
SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass the login screen using browser developer tools, gaining access to restricted parts of the application.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
3.0.48
Credits
Souvik Kandar of Microsec (microsec.io)
References
www.cisa.gov/news-events/ics-advisories/icsa-25-329-06