The affected product has an authentication bypass, which could make it vulnerable to an attacker impersonating a system user. Successful exploitation of this vulnerability could allow an authenticated attacker to impersonate other users of the system and perform (potentially administrative) actions on behalf of those users if the single sign-on feature (“Allow logon without password”) is enabled.
Use of client-side authentication
SIPORT MP: Versions 3.2.1 and prior
Siemens has released an updated version (v3.2.1).