Lucene search

K
cvelistSiemensCVELIST:CVE-2021-40354
HistorySep 14, 2021 - 10:47 a.m.

CVE-2021-40354

2021-09-1410:47:58
CWE-267
siemens
www.cve.org
4
teamcenter
vulnerability
access control
account takeover
surrogate functionality
user profile
application
inbox
security

AI Score

7

Confidence

High

EPSS

0.001

Percentile

23.8%

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The “surrogate” functionality on the user profile of the application does not perform sufficient access control that could lead to an account takeover. Any profile on the application can perform this attack and access any other user assigned tasks via the “inbox/surrogate tasks”.

CNA Affected

[
  {
    "product": "Teamcenter V12.4",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V12.4.0.8"
      }
    ]
  },
  {
    "product": "Teamcenter V13.0",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V13.0.0.7"
      }
    ]
  },
  {
    "product": "Teamcenter V13.1",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V13.1.0.5"
      }
    ]
  },
  {
    "product": "Teamcenter V13.2",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < 13.2.0.2"
      }
    ]
  }
]

AI Score

7

Confidence

High

EPSS

0.001

Percentile

23.8%

Related for CVELIST:CVE-2021-40354