cbcvebase.

Siemens Sinema Remote Connect Server vulnerabilities

70 known vulnerabilities affecting siemens/sinema_remote_connect_server.

Total CVEs
70
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL15HIGH27MEDIUM25LOW3

Vulnerabilities

Page 2 of 4
CVE-2022-25235P3CRITICALCVSS 9.8fixed in 3.12022-02-16
CVE-2022-25235 [CRITICAL] CWE-116 CVE-2022-25235: xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as che xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
nvd
CVE-2019-6570P3HIGHCVSS 8.8fixed in 2.0vAll versions < V2.02019-04-17
CVE-2019-6570 [HIGH] CWE-280 CVE-2019-6570: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to in A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking of user permissions, an attacker may access URLs that require special authorization. An attacker must have access to a low privileged account in order to exploit the vulnerability.
nvd
CVE-2024-39867P3HIGHCVSS 7.3fixed in 3.2v3.2+1 more2024-07-09
CVE-2024-39867 [HIGH] CWE-425 CVE-2024-39867: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate the authentication when performing certain actions in the web interface allowing an unauthenticated attacker to access and edit device configuration information of devices for which they have no privileges.
nvd
CVE-2020-25239P3HIGHCVSS 8.8fixed in 3.0vAll versions < V3.02021-03-15
CVE-2020-25239 [HIGH] CWE-863 CVE-2020-25239: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webse A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be changed to add a rogue server by an attacker authenticating with unprivilege user rights.
nvd
CVE-2024-39868P3HIGHCVSS 7.3fixed in 3.2v3.2+1 more2024-07-09
CVE-2024-39868 [HIGH] CWE-425 CVE-2024-39868: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate the authentication when performing certain actions in the web interface allowing an unauthenticated attacker to access and edit VxLAN configuration information of networks for which they have no privileges.
nvd
CVE-2020-25240P3HIGHCVSS 8.8fixed in 3.0vAll versions < V3.02021-03-15
CVE-2020-25240 [HIGH] CWE-863 CVE-2020-25240: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unprivile A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can access services when guessing the url. An attacker could impact availability, integrity and gain information from logs and templates of the service.
nvd
CVE-2021-45960P3HIGHCVSS 8.8fixed in 3.12022-01-01
CVE-2021-45960 [HIGH] CWE-682 CVE-2021-45960: In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
nvd
CVE-2022-22826P3HIGHCVSS 8.8fixed in 3.12022-01-10
CVE-2022-22826 [HIGH] CWE-190 CVE-2022-22826: nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2022-22827P3HIGHCVSS 8.8fixed in 3.12022-01-10
CVE-2022-22827 [HIGH] CWE-190 CVE-2022-22827: storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2022-22825P3HIGHCVSS 8.8fixed in 3.12022-01-10
CVE-2022-22825 [HIGH] CWE-190 CVE-2022-22825: lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2022-32253P3HIGHCVSS 7.5fixed in 3.1fixed in V3.12022-06-14
CVE-2022-32253 [HIGH] CWE-20 CVE-2022-32253: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). Due to im A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). Due to improper input validation, the OpenSSL certificate's password could be printed to a file reachable by an attacker.
nvd
CVE-2024-39873P3HIGHCVSS 7.5fixed in 3.2v3.2+1 more2024-07-09
CVE-2024-39873 [HIGH] CWE-307 CVE-2024-39873: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The a A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its web API. This could allow an attacker to learn user credentials that are vulnerable to brute force attacks.
nvd
CVE-2022-25314P3HIGHCVSS 7.5fixed in 3.12022-02-18
CVE-2022-25314 [HIGH] CWE-190 CVE-2022-25314: In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString. In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
nvd
CVE-2024-39874P3HIGHCVSS 7.5fixed in 3.2v3.2+1 more2024-07-09
CVE-2024-39874 [HIGH] CWE-307 CVE-2024-39874: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The a A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its Client Communication component. This could allow an attacker to learn user credentials that are vulnerable to brute force attacks.
nvd
CVE-2020-7595P3HIGHCVSS 7.5fixed in 3.02020-01-21
CVE-2020-7595 [HIGH] CWE-835 CVE-2020-7595: xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-fi xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
nvd
CVE-2022-32254P3HIGHCVSS 7.5fixed in 3.1fixed in V3.12022-06-14
CVE-2022-32254 [HIGH] CWE-532 CVE-2022-32254: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A customi A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A customized HTTP POST request could force the application to write the status of a given user to a log file, exposing sensitive user information that could provide valuable guidance to an attacker.
nvd
CVE-2022-32261P3HIGHCVSS 7.5fixed in 3.1fixed in V3.12022-06-14
CVE-2022-32261 [HIGH] CWE-233 CVE-2022-32261: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a misconfiguration in the APT update. This could allow an attacker to add insecure packages to the application.
nvd
CVE-2021-46143P3HIGHCVSS 7.8fixed in 3.12022-01-06
CVE-2021-46143 [HIGH] CWE-190 CVE-2021-46143: In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_gro In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.
nvd
CVE-2024-39870P3HIGHCVSS 7.8fixed in 3.2v3.2+1 more2024-07-09
CVE-2024-39870 [HIGH] CWE-602 CVE-2024-39870: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The a A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privilege could use this modify users outside of their own scope as well as to escalate privileges.
nvd
CVE-2022-23990P3HIGHCVSS 7.5fixed in 3.12022-01-26
CVE-2022-23990 [HIGH] CWE-190 CVE-2022-23990: Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
nvd
Siemens Sinema Remote Connect Server vulnerabilities | cvebase