SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass the login screen using browser developer tools, gaining access to restricted parts of the application.
History

Tue, 25 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Nov 2025 18:15:00 +0000


Tue, 25 Nov 2025 17:45:00 +0000

Type Values Removed Values Added
Description SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass the login screen using browser developer tools, gaining access to restricted parts of the application.
Title Missing Authentication for Critical Function in SiRcom SMART Alert (SiSA)
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2025-11-25T17:36:24.451Z

Updated: 2025-11-25T20:21:13.361Z

Reserved: 2025-11-20T16:46:56.591Z

Link: CVE-2025-13483

cve-icon Vulnrichment

Updated: 2025-11-25T20:21:10.146Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-25T18:15:49.780

Modified: 2025-11-25T22:16:16.690

Link: CVE-2025-13483

cve-icon Redhat

No data.