CVE-2022-23102
published 2022-02-09CVE-2022-23102: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An…
PriorityP342medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EXPLOIT
EPSS
5.27%
91.6th percentile
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | sinema_remote_connect_server | <= 2.0 | — |
| siemens | sinema_remote_connect_server | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9wrg-64cr-9jvf: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2
ghsa_unreviewed·2022-02-10
CVE-2022-23102 [MEDIUM] CWE-601 GHSA-9wrg-64cr-9jvf: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks.
CISA ICS
Siemens SINEMA Remote Connect Server
cisa_ics·2022-03-09·CVSS 6.1
[MEDIUM] Siemens SINEMA Remote Connect Server
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEMA Remote Connect Server
Last RevisedMarch 09, 2022
Alert CodeICSA-22-041-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 5.4
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEMA Remote Connect Server
- Vulnerability: Open Redirect
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to use a specially crafted link to steal login credentials.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of SINEMA Remote Server, a management platform for remote networks, are affect
No detection rules found.
Nuclei
SINEMA Remote Connect Server < V2.0 - Open Redirect
nuclei·CVSS 6.1
CVE-2022-23102 [MEDIUM] SINEMA Remote Connect Server < V2.0 - Open Redirect
SINEMA Remote Connect Server "
internal: true
# digest: 490a004630440220310baaa7896692d85263aba242d7bca651532847bf781c4d5e14d6513e68d184022071029f83828113e404783b55f9c882cefec86d8ca886aaa2b9f60e7990a5a5ff:922c64590222798bb761d5b6d8e72950
http://packetstormsecurity.com/files/165966/SIEMENS-SINEMA-Remote-Connect-1.0-SP3-HF1-Open-Redirection.htmlhttp://seclists.org/fulldisclosure/2022/Feb/20https://cert-portal.siemens.com/productcert/pdf/ssa-654775.pdfhttp://packetstormsecurity.com/files/165966/SIEMENS-SINEMA-Remote-Connect-1.0-SP3-HF1-Open-Redirection.htmlhttp://seclists.org/fulldisclosure/2022/Feb/20https://cert-portal.siemens.com/productcert/pdf/ssa-654775.pdf
2022-02-09
Published