PT-2024-2147 · Siemens · Sinema Remote Connect Client

Published

2024-03-12

·

Updated

2024-03-25

·

CVE-2024-22045

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions SINEMA Remote Connect Client versions prior to V3.1 SP1
Description A vulnerability has been identified in the SINEMA Remote Connect Client, where sensitive information is placed into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information. This information is also available via the web interface of the product. The vulnerability is related to a potential information leak, which could allow a remote attacker to impact the confidentiality and integrity of protected information.
Recommendations For SINEMA Remote Connect Client versions prior to V3.1 SP1, update to version V3.1 SP1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation. Additionally, limit access to the web interface of the product to authorized personnel only.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-02056
CVE-2024-22045

Affected Products

Sinema Remote Connect Client