CVE-2025-27494 Details
Description
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize input for the pubkey endpoint of the REST API. This could allow an authenticated remote administrator to escalate privileges by injecting arbitrary commands that are executed with root privileges.
A vulnerability exists in Siemens SiPass integrated AC5102 (ACC-G2) and ACC-AP, all versions prior to 6.4.9. The issue arises because affected devices do not properly sanitize input for the pubkey endpoint of the REST API, allowing an authenticated remote administrator to inject arbitrary commands that are executed with root privileges. Additionally, a similar input validation flaw has been identified in the telnet command line interface, where an authenticated local administrator could also escalate privileges by injecting commands that are executed with root rights.
Users are advised to update to the latest versions of the affected products. For SiPass integrated AC5102 (ACC-G2) and ACC-AP, specific product remediations can be found in the Siemens Security Advisory SSA-515903. Additionally, it is recommended to set a strong password for the administrator account.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-515903.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| siemens sipass integrated ac5102 (acc-g2) firmware | < 6.4.9 |
CPE
Remediation
| |
| siemens sipass integrated ac5102 (acc-g2) | All versions |
CPE
Remediation
| |
| siemens sipass integrated acc-ap firmware | < 6.4.9 |
CPE
Remediation
| |
| siemens sipass integrated acc-ap | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 22, 2025 | Initial Analysis | [email protected] |
| Mar 11, 2025 | New CVE Received | [email protected] |