PT-2022-2157 · Siemens · Sinema Remote Connect Server

A. Ovsyannikova

·

Published

2022-02-09

·

Updated

2022-02-18

·

CVE-2022-23102

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SINEMA Remote Connect Server versions prior to V2.0
Description A vulnerability has been identified that allows for an open redirect, potentially leading to phishing attacks. An attacker could trick a valid authenticated user into clicking a malicious link. This issue is related to the server's handling of URL redirects, which can be exploited by a remote attacker to conduct phishing attacks using a specially crafted link.
Recommendations For versions prior to V2.0, update to version V2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to external links from within the SINEMA Remote Connect Server to minimize the risk of exploitation. Avoid using links from untrusted sources until the issue is resolved.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02114
CVE-2022-23102

Affected Products

Sinema Remote Connect Server