CVE-2021-40354

HIGH

Teamcenter Visualization < 12.4.0.8 - Improper Privilege Management via Surrogate Functionality

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The "surrogate" functionality on the user profile of the application does not perform sufficient access control that could lead to an account takeover. Any profile on the application can perform this attack and access any other user assigned tasks via the "inbox/surrogate tasks".

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://cert-portal.siemens.com/productcert/pdf/ssa-987403.pdf

Scores

CVSS v3 7.1
EPSS 0.0057
EPSS Percentile 42.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Details

CWE
CWE-269 CWE-267
Status published
Products (1)
siemens/teamcenter_visualization 12.4.0 - 12.4.0.8
Published Sep 14, 2021
Tracked Since Feb 18, 2026