ZeroHour

CVE-2020-7591

CVSS 3.1
8.8 high
EPSS
1%p72
Published
()
Modified
Description

A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow an authenticated attacker to impersonate other users of the system and perform (potentially administrative) actions on behalf of those users if the single sign-on feature ("Allow logon without password") is enabled.

Vendors
siemens
Products
siport mp
Weakness
CWE-603, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.