PT-2022-21187 · Siemens · Sinema Remote Connect Server

CVE-2022-32262

·

Published

2022-06-14

·

Updated

2024-07-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SINEMA Remote Connect Server versions prior to V3.1
Description A vulnerability has been identified in the SINEMA Remote Connect Server, where the affected application contains a file upload server that is vulnerable to command injection. This vulnerability allows an attacker to achieve arbitrary code execution.
Recommendations For versions prior to V3.1, update to version V3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the file upload server to minimize the risk of exploitation.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-32262

Affected Products

Sinema Remote Connect Server