PT-2024-2147 · Siemens · Sinema Remote Connect Client
Published
2024-03-12
·
Updated
2024-03-25
·
CVE-2024-22045
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SINEMA Remote Connect Client versions prior to V3.1 SP1
Description
A vulnerability has been identified in the SINEMA Remote Connect Client, where sensitive information is placed into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information. This information is also available via the web interface of the product. The vulnerability is related to a potential information leak, which could allow a remote attacker to impact the confidentiality and integrity of protected information.
Recommendations
For SINEMA Remote Connect Client versions prior to V3.1 SP1, update to version V3.1 SP1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation. Additionally, limit access to the web interface of the product to authorized personnel only.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinema Remote Connect Client