VDB

CVE-2021-40354

CVE-2021-40354 PUBLISHED CVSS 5.5 MEDIUM

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The "surrogate" functionality on the user profile of the application does not perform sufficient access control that could lead to an account takeover. Any profile on the application can perform this attack and access any other user assigned tasks via the "inbox/surrogate tasks".

EPSS 0.21% · 43.3th percentile

Risk Scores

CVSS 2.0
5.5
EPSS Score
0.21%
43.3th percentile

Affected Products

VendorProductVersions
SiemensTeamcenter V12.4All versions < V12.4.0.8
SiemensTeamcenter V13.2All versions < 13.2.0.2
SiemensTeamcenter V13.0All versions < V13.0.0.7
siemensteamcenter_visualization13.1.0, 13.2.0, 12.4.0
SiemensTeamcenter V13.1All versions < V13.1.0.5

Timeline

  • Apr 13, 2021 CVE Published
  • Sep 15, 2021 EPSS Score
  • Oct 5, 2021 EPSS Score
  • Oct 11, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 8, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 6, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jun 29, 2022 EPSS Score
  • Aug 27, 2022 EPSS Score
  • Oct 23, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›