CVE-2020-7591
Summary
| CVE | CVE-2020-7591 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-15 19:15:00 UTC |
| Updated | 2022-06-15 03:15:00 UTC |
| Description | A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow an authenticated attacker to impersonate other users of the system and perform (potentially administrative) actions on behalf of those users if the single sign-on feature ("Allow logon without password") is enabled. |
Risk And Classification
Problem Types: CWE-603
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Siemens SIPORT MP | CISA | MISC | us-cert.cisa.gov | |
| cert-portal.siemens.com/productcert/pdf/ssa-384879.pdf | MISC | cert-portal.siemens.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.