Home
CRITICAL: 9.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HCRITICAL: 9.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HDefault status
unknown
Any version before V6.4.9
affected
Default status
unknown
Any version before V6.4.9
affected
Description
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize input for the pubkey endpoint of the REST API. This could allow an authenticated remote administrator to escalate privileges by injecting arbitrary commands that are executed with root privileges.
Problem types
CWE-20: Improper Input Validation
Product status
Any version before V6.4.9
Any version before V6.4.9
References
cert-portal.siemens.com/productcert/html/ssa-515903.html