A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize input for the pubkey endpoint of the REST API. This could allow an authenticated remote administrator to escalate privileges by injecting arbitrary commands that are executed with root privileges.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Aug 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Siemens
Siemens sipass Integrated Ac5102 \(acc-g2\) Siemens sipass Integrated Ac5102 \(acc-g2\) Firmware Siemens sipass Integrated Acc-ap Siemens sipass Integrated Acc-ap Firmware |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:h:siemens:sipass_integrated_ac5102_\(acc-g2\):-:*:*:*:*:*:*:* cpe:2.3:h:siemens:sipass_integrated_acc-ap:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sipass_integrated_ac5102_\(acc-g2\)_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:sipass_integrated_acc-ap_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Siemens
Siemens sipass Integrated Ac5102 \(acc-g2\) Siemens sipass Integrated Ac5102 \(acc-g2\) Firmware Siemens sipass Integrated Acc-ap Siemens sipass Integrated Acc-ap Firmware |
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 11 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Mar 2025 10:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize input for the pubkey endpoint of the REST API. This could allow an authenticated remote administrator to escalate privileges by injecting arbitrary commands that are executed with root privileges. | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: siemens
Published: 2025-03-11T09:48:34.182Z
Updated: 2025-03-11T13:21:07.671Z
Reserved: 2025-02-26T18:05:35.964Z
Link: CVE-2025-27494

Updated: 2025-03-11T13:21:02.395Z

Status : Analyzed
Published: 2025-03-11T10:15:19.783
Modified: 2025-08-22T17:49:43.953
Link: CVE-2025-27494

No data.