PT-2022-21178 · Siemens · Sinema Remote Connect Server
Published
2022-06-14
·
Updated
2024-07-09
·
CVE-2022-32252
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SINEMA Remote Connect Server versions prior to V3.1
Description
A vulnerability has been identified where the application does not perform integrity checks of update packages. This could allow an admin user to be tricked into installing a malicious package, potentially granting root privileges to an attacker.
Recommendations
For versions prior to V3.1, update to version V3.1 or later to resolve the issue. As a temporary workaround, consider validating update packages manually before installation to minimize the risk of exploitation. Restrict access to the update package installation process to authorized personnel only.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinema Remote Connect Server