MEDIUM🇵🇱 Wersja polska

CVE-2022-32259

CVSS 6.5v3.1pub. 2022-06-14upd. 2024-11-21

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The system images for installation or update of the affected application contain unit test scripts with sensitive information. An attacker could gain information about testing architecture and also tamper with test configuration.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  • Siemens Sinema Remote Connect Server

    APP
    Siemens
    < 3.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product

SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego

CVE-2024-39872CRITICAL9.3PL ✓same product

Privilege escalation w SINEMA Remote Connect Server przez tymczasowe pliki aktualizacji

CVE-2022-32257CRITICAL9.8PL ✓same product

Siemens SINEMA Remote Connect Server — brak kontroli dostępu prowadzący do RCE

CVE-2022-25315CRITICAL9.8PL ✓same product

Integer overflow w libexpat (storeRawNames) — RCE bez uwierzytelnienia

CVE-2022-25235CRITICAL9.8PL ✓same product

Brak walidacji kodowania UTF-8 w bibliotece Expat (libexpat)