A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize input for the pubkey endpoint of the REST API. This could allow an authenticated remote administrator to escalate privileges by injecting arbitrary commands that are executed with root privileges.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Aug 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens sipass Integrated Ac5102 \(acc-g2\) Siemens sipass Integrated Ac5102 \(acc-g2\) Firmware Siemens sipass Integrated Acc-ap Siemens sipass Integrated Acc-ap Firmware |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:h:siemens:sipass_integrated_ac5102_\(acc-g2\):-:*:*:*:*:*:*:* cpe:2.3:h:siemens:sipass_integrated_acc-ap:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sipass_integrated_ac5102_\(acc-g2\)_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:sipass_integrated_acc-ap_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Siemens
Siemens sipass Integrated Ac5102 \(acc-g2\) Siemens sipass Integrated Ac5102 \(acc-g2\) Firmware Siemens sipass Integrated Acc-ap Siemens sipass Integrated Acc-ap Firmware |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 11 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Mar 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize input for the pubkey endpoint of the REST API. This could allow an authenticated remote administrator to escalate privileges by injecting arbitrary commands that are executed with root privileges. | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published: 2025-03-11T09:48:34.182Z
Updated: 2025-03-11T13:21:07.671Z
Reserved: 2025-02-26T18:05:35.964Z
Link: CVE-2025-27494
Updated: 2025-03-11T13:21:02.395Z
Status : Analyzed
Published: 2025-03-11T10:15:19.783
Modified: 2025-08-22T17:49:43.953
Link: CVE-2025-27494
No data.