The vendor explicitly identifies these products as affected by this CVE.
- SiPass integrated V2.76
- SiPass integrated V2.80
- SiPass integrated V2.85
- Summary
- Affected applications insufficiently limit the access to the internal activity feed database. This could allow an unauthenticated remote attacker to read, modify or delete activity feed entries.
- Remediation
- Update to V2.76 SP2 and then download and execute the SiPass integrated Component Manager: https://support.industry.siemens.com/cs/ww/en/view/109802587/
