VDB
CVE-2021-40354
CVE-2021-40354
PUBLISHED
CVSS 5.5 MEDIUM
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The "surrogate" functionality on the user profile of the application does not perform sufficient access control that could lead to an account takeover. Any profile on the application can perform this attack and access any other user assigned tasks via the "inbox/surrogate tasks".
EPSS 0.21% · 43.3th percentile
Risk Scores
CVSS 2.0
5.5
EPSS Score
0.21%
43.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Teamcenter V12.4 | All versions < V12.4.0.8 |
| Siemens | Teamcenter V13.2 | All versions < 13.2.0.2 |
| Siemens | Teamcenter V13.0 | All versions < V13.0.0.7 |
| siemens | teamcenter_visualization | 13.1.0, 13.2.0, 12.4.0 |
| Siemens | Teamcenter V13.1 | All versions < V13.1.0.5 |
Exploit Intelligence
- This proof-of-concept script exploits a vulnerability in OpenSSH versions prior to 7.4 (CVE-2016-10708) by sending unexpected `SSH_MSG_NEWKEYS` packets. (github-poc)
- This proof-of-concept script exploits a vulnerability in OpenSSH versions prior to 7.4 (CVE-2016-10708) by sending unexpected `SSH_MSG_NEWKEYS` packets. (github-poc)
- This proof-of-concept script exploits a vulnerability in OpenSSH versions prior to 7.4 (CVE-2016-10708) by sending unexpected `SSH_MSG_NEWKEYS` packets. (github-poc)
- This proof-of-concept script exploits a vulnerability in OpenSSH versions prior to 7.4 (CVE-2016-10708) by sending unexpected `SSH_MSG_NEWKEYS` packets. (github-poc)
- This proof-of-concept script exploits a vulnerability in OpenSSH versions prior to 7.4 (CVE-2016-10708) by sending unexpected `SSH_MSG_NEWKEYS` packets. (github-poc)
- https://cert-portal.siemens.com/productcert/pdf/ssa-987403.pdf (circl)
Timeline
- Apr 13, 2021 CVE Published
- Sep 15, 2021 EPSS Score
- Oct 5, 2021 EPSS Score
- Oct 11, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 8, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 6, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jun 29, 2022 EPSS Score
- Aug 27, 2022 EPSS Score
- Oct 23, 2022 EPSS Score
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-847986.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-549234.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-208530.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-288459.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-987403.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-535380.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-334944.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-676336.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-997732.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-835377.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-109294.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-453715.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-692317.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-756638.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-316383.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-330339.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-500748.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-535997.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-150692.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-413407.pdf advisory
…and 2 more