PT-2022-21181 · Siemens · Sinema Remote Connect Server

Published

2022-06-14

·

Updated

2024-07-09

·

CVE-2022-32255

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SINEMA Remote Connect Server versions prior to V3.1
Description A vulnerability has been identified in the SINEMA Remote Connect Server, where a web service lacks proper access control for some endpoints, potentially leading to unauthorized access to limited information.
Recommendations For versions prior to V3.1, update to version V3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable web service endpoints until a patch is available.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-32255

Affected Products

Sinema Remote Connect Server