PT-2025-49836 · Unknown · Sinema Remote Connect Server

Published

2025-12-09

·

Updated

2025-12-09

·

CVE-2025-40818

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SINEMA Remote Connect Server versions prior to 3.2 SP4
Description The software contains improperly protected private SSL/TLS keys on the server. An authenticated attacker could read these keys, potentially enabling man-in-the-middle attacks, traffic decryption, or unauthorized access to services that trust these certificates.
Recommendations Update to version 3.2 SP4 or later.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2025-15670
CVE-2025-40818

Affected Products

Sinema Remote Connect Server