Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-71440
HistorySep 15, 2021 - 12:00 a.m.

Siemens Teamcenter Access Control Error Vulnerability

2021-09-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
siemens teamcenter
access control
vulnerability
user profile
account takeover
inbox
surrogate tasks

EPSS

0.001

Percentile

23.8%

An access control error vulnerability exists in Siemens Teamcenter, a product lifecycle management computer software application from Siemens, Germany. The vulnerability is due to a failure of the surrogate function on the application user profile to perform sufficient access control, which could lead to account takeover. An attacker could exploit the vulnerability to access tasks assigned by any other user via inbox/surrogate tasks.

EPSS

0.001

Percentile

23.8%

Related for CNVD-2021-71440