PT-2022-18310 · Siemens · Sinema Remote Connect Server

Published

2022-06-14

·

Updated

2024-07-09

·

CVE-2022-27221

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SINEMA Remote Connect Server versions prior to V3.1
Description A security issue has been identified that allows an attacker in a machine-in-the-middle position to obtain plaintext secret values. This is achieved by observing length differences during a series of guesses where a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, also known as a "BREACH" attack.
Recommendations For versions prior to V3.1, update to version V3.1 or later to resolve the issue. As a temporary workaround, consider implementing additional security measures to prevent machine-in-the-middle attacks, such as enhancing encryption and authentication protocols. Restrict access to sensitive data and consider using secure communication protocols to minimize the risk of exploitation.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2022-27221

Affected Products

Sinema Remote Connect Server