CVE-2021-31338External Control of System or Configuration Setting in Siemens Sinema Remote Connect

Severity
7.8HIGHNVD
EPSS
0.1%
top 84.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 19
Latest updateMay 24

Description

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.0 SP1). Affected devices allow to modify configuration settings over an unauthenticated channel. This could allow a local attacker to escalate privileges and execute own code on the device.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5siemens/sinema_remote_connect_clientAll versions < V3.0 SP1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qcvh-w68r-q938: A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V32022-05-24
CVEList
CVE-2021-31338: A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V32021-08-19
CVE-2021-31338 — Siemens vulnerability | cvebase