cbcvebase.

Siemens Sinema Remote Connect Server vulnerabilities

70 known vulnerabilities affecting siemens/sinema_remote_connect_server.

Total CVEs
70
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL15HIGH27MEDIUM25LOW3

Vulnerabilities

Page 1 of 4
CVE-2021-40438P1CRITICALCVSS 9.0KEVPoCRansomwarefixed in 3.1v3.22021-09-16
CVE-2021-40438 [CRITICAL] CWE-918 CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
nvd
CVE-2021-20093P2CRITICALCVSS 9.1fixed in 3.0v3.02021-06-16
CVE-2021-20093 [CRITICAL] CWE-125 CVE-2021-20093: A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticat A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.
nvd
CVE-2021-34798P3HIGHCVSS 7.5fixed in 3.12021-09-16
CVE-2021-34798 [HIGH] CWE-476 CVE-2021-34798: Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTT Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
nvd
CVE-2022-25236P2CRITICALCVSS 9.8fixed in 3.12022-02-16
CVE-2022-25236 [CRITICAL] CWE-668 CVE-2022-25236: xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator chara xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
nvd
CVE-2024-39571P2HIGHCVSS 8.8fixed in 3.2v3.2+1 more2024-07-09
CVE-2024-39571 [HIGH] CWE-77 CVE-2024-39571: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to command injection due to missing server side input sanitation when loading SNMP configurations. This could allow an attacker with the right to modify the SNMP configuration to execute arbitrary code with root privileges
nvd
CVE-2022-32262P2CRITICALCVSS 9.8fixed in 3.1fixed in V3.12022-06-14
CVE-2022-32262 [CRITICAL] CWE-77 CVE-2022-32262: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a file upload server that is vulnerable to command injection. An attacker could use this to achieve arbitrary code execution.
nvd
CVE-2022-23102P3MEDIUMCVSS 6.1PoC≤ 2.0vAll versions < V2.02022-02-09
CVE-2022-23102 [MEDIUM] CWE-601 CVE-2022-23102: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks.
nvd
CVE-2024-39872P2CRITICALCVSS 9.9fixed in 3.2v3.2+1 more2024-07-09
CVE-2024-39872 [CRITICAL] CWE-378 CVE-2024-39872: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The a A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly assign rights to temporary files created during its update process. This could allow an authenticated attacker with the 'Manage firmware updates' role to escalate their privileges on the underlying OS level.
nvd
CVE-2022-32260P2CRITICALCVSS 9.8fixed in 3.1fixed in V3.2 SP12022-06-14
CVE-2022-32260 [CRITICAL] CWE-286 CVE-2022-32260: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The a A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application creates temporary user credentials for UMC (User Management Component) users. An attacker could use these temporary credentials for authentication bypass in certain scenarios.
nvd
CVE-2024-39570P2HIGHCVSS 8.8fixed in 3.2v3.2+1 more2024-07-09
CVE-2024-39570 [HIGH] CWE-77 CVE-2024-39570: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to command injection due to missing server side input sanitation when loading VxLAN configurations. This could allow an authenticated attacker to execute arbitrary code with root privileges.
nvd
CVE-2019-13918P2CRITICALCVSS 9.8fixed in 2.0v2.02019-09-13
CVE-2019-13918 [CRITICAL] CWE-307 CVE-2019-13918: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The w A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to the vulnerable software, requiring no privileges and no user interaction. The vulnerability could allow full a
nvd
CVE-2022-32251P3CRITICALCVSS 9.8fixed in 3.1fixed in V3.12022-06-14
CVE-2022-32251 [CRITICAL] CWE-306 CVE-2022-32251: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is a missing authentication verification for a resource used to change the roles and permissions of a user. This could allow an attacker to change the permissions of any user and gain the privileges of an administrative user.
nvd
CVE-2022-32257P3CRITICALCVSS 9.8fixed in 3.2fixed in V3.22024-03-12
CVE-2022-32257 [CRITICAL] CWE-284 CVE-2022-32257: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to resources and potentially lead to code execution.
nvd
CVE-2022-25315P3CRITICALCVSS 9.8fixed in 3.12022-02-18
CVE-2022-25315 [CRITICAL] CWE-190 CVE-2022-25315: In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
nvd
CVE-2024-39865P3HIGHCVSS 8.8fixed in 3.2v3.2+1 more2024-07-09
CVE-2024-39865 [HIGH] CWE-434 CVE-2024-39865: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The a A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. As part of this backup, files can be restored without correctly checking the path of the restored file. This could allow an attacker with access to the backup encryption key to upload ma
nvd
CVE-2022-22822P3CRITICALCVSS 9.8fixed in 3.12022-01-10
CVE-2022-22822 [CRITICAL] CWE-190 CVE-2022-22822: addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2024-39866P3HIGHCVSS 8.8fixed in 3.2v3.2+1 more2024-07-09
CVE-2024-39866 [HIGH] CWE-267 CVE-2024-39866: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The a A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. This could allow an attacker with access to the backup encryption key and with the right to upload backup files to create a user with administrative privileges.
nvd
CVE-2022-23852P3CRITICALCVSS 9.8fixed in 3.12022-01-24
CVE-2022-23852 [CRITICAL] CWE-190 CVE-2022-23852: Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
nvd
CVE-2022-22823P3CRITICALCVSS 9.8fixed in 3.12022-01-10
CVE-2022-22823 [CRITICAL] CWE-190 CVE-2022-22823: build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2022-22824P3CRITICALCVSS 9.8fixed in 3.12022-01-10
CVE-2022-22824 [CRITICAL] CWE-190 CVE-2022-22824: defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
Siemens Sinema Remote Connect Server vulnerabilities | cvebase