CVE-2025-13483

HIGH

SiRcom SMART Alert (SiSA) >=3.0.48 <3.0.48 - Unauthenticated Backend API Access Bypass

Title source: llm
STIX 2.1

Description

SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass the login screen using browser developer tools, gaining access to restricted parts of the application.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource government-resource
https://www.cisa.gov/news-events/ics-advisories/icsa-25-329-06

Scores

CVSS v4 8.8
EPSS 0.0032
EPSS Percentile 23.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
SiRcom/SMART Alert (SiSA 3.0.48
Published Nov 25, 2025
Tracked Since Feb 18, 2026