PT-2022-21182 · Siemens · Sinema Remote Connect Server

Published

2022-06-14

·

Updated

2024-07-09

·

CVE-2022-32256

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SINEMA Remote Connect Server versions prior to V3.1
Description A vulnerability has been identified in the SINEMA Remote Connect Server, where the web service lacks proper access control for some endpoints. This could lead to low privileged users accessing privileged information.
Recommendations For versions prior to V3.1, update to version V3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable endpoints to minimize the risk of exploitation.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-32256

Affected Products

Sinema Remote Connect Server