Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2020-7591

A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow an authenticated attacker to impersonate other users of the system and perform (potentially administrative) actions on behalf of those users if the single sign-on feature (“Allow logon without password”) is enabled.

CVE
#vulnerability#pdf#auth

%PDF-1.5 %���� 1 0 obj << /D [2 0 R /XYZ 70.866 771.024 null] >> endobj 3 0 obj << /D [2 0 R /XYZ 70.866 646.963 null] >> endobj 4 0 obj << /D [2 0 R /XYZ 70.866 473.966 null] >> endobj 5 0 obj << /D [2 0 R /XYZ 70.866 390.853 null] >> endobj 6 0 obj << /D [7 0 R /XYZ 85.039 702.996 null] >> endobj 8 0 obj << /D [7 0 R /XYZ 70.866 515.559 null] >> endobj 9 0 obj << /S /GoTo /D [2 0 R /Fit] >> endobj 2 0 obj << /Contents 10 0 R /Type /Page /Resources 11 0 R /Parent 12 0 R /Annots [13 0 R 14 0 R 15 0 R 16 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 13 0 obj << /A << /S /URI /Type /Action /URI (https://support.industry.siemens.com/cs/ww/en/view/109781856) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 499.366 518.276 510.783] >> endobj 15 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [131.954 176.764 248.203 188.3] >> endobj 16 0 obj << /A << /S /URI /Type /Action /URI (https://cwe.mitre.org/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [69.87 87.1 163.926 98.637] >> endobj 17 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [224.029 678.089 507.331 692.037] >> endobj 11 0 obj << /ProcSet [/PDF /Text] /Font << /F53 18 0 R /F50 19 0 R >> >> endobj 10 0 obj << /Filter /FlateDecode /Length 3000 >> stream xڵZ�s�8�_ᷓgjF��ν�i��^��b�;;�>(��h*�^KN6����-Ev���LSQ  �:< ���ӓ�O2h�# ���8�Jk"�Lg���$��YY GL��$K׫�� �_l�x��W ��a��l�nL�^-f�>;�������o’�ӓ�N(0�I��t~���p0�o� B�u

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda