A vulnerability has been identified in Industrial Edge Management (All versions < V1.3). An unauthenticated attacker could change the the password of any user in the system under certain circumstances. With this an attacker could impersonate any valid user on an affected system.
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-692317.pdf | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: siemens
Published: 2021-09-14T10:47:48
Updated: 2021-09-14T10:47:48
Reserved: 2021-07-21T00:00:00
Link: CVE-2021-37184
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-09-14T11:15:25.770
Modified: 2021-09-24T15:01:29.477
Link: CVE-2021-37184
JSON object: View
Redhat Information
No data.
CWE