A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The system images for installation or update of the affected application contain unit test scripts with sensitive information. An attacker could gain information about testing architecture and also tamper with test configuration.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NSiemens Sinema Remote Connect Server
APPSiemens< 3.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓ten sam produkt
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2024-39872CRITICAL9.3PL ✓ten sam produkt
Privilege escalation w SINEMA Remote Connect Server przez tymczasowe pliki aktualizacji
CVE-2022-32257CRITICAL9.8PL ✓ten sam produkt
Siemens SINEMA Remote Connect Server — brak kontroli dostępu prowadzący do RCE
CVE-2022-25315CRITICAL9.8PL ✓ten sam produkt
Integer overflow w libexpat (storeRawNames) — RCE bez uwierzytelnienia
CVE-2022-25235CRITICAL9.8PL ✓ten sam produkt
Brak walidacji kodowania UTF-8 w bibliotece Expat (libexpat)