PT-2019-13475 · Siemens · Sinema Remote Connect Server
Published
2019-09-13
·
Updated
2021-11-02
·
CVE-2019-13919
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SINEMA Remote Connect Server versions prior to V2.0 SP1
Description
A security issue has been identified where certain pages, intended for privileged users, can be accessed by non-privileged users. This can be exploited by an attacker with network access and valid web interface credentials, without requiring user interaction. The issue allows unauthorized access to sensitive information, excluding passwords. At the time of reporting, there were no known public exploits.
Recommendations
For versions prior to V2.0 SP1, update to V2.0 SP1 or later to resolve the issue.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinema Remote Connect Server