cbcvebase.

Siemens Sinema Remote Connect Server vulnerabilities

70 known vulnerabilities affecting siemens/sinema_remote_connect_server.

Total CVEs
70
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL15HIGH27MEDIUM25LOW3

Vulnerabilities

Page 3 of 4
CVE-2022-32258P3HIGHCVSS 7.5fixed in 3.1fixed in V3.12022-06-14
CVE-2022-32258 [HIGH] CWE-448 CVE-2022-32258: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains an older feature that allows to import device configurations via a specific endpoint. An attacker could use this vulnerability for information disclosure.
nvd
CVE-2022-32252P3HIGHCVSS 7.8fixed in 3.1fixed in V3.12022-06-14
CVE-2022-32252 [HIGH] CWE-345 CVE-2022-32252: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The appli A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The application does not perform the integrity check of the update packages. Without validation, an admin user might be tricked to install a malicious package, granting root privileges to an attacker.
nvd
CVE-2022-29034P3MEDIUMCVSS 6.1fixed in 3.1fixed in V3.12022-06-14
CVE-2022-29034 [MEDIUM] CWE-79 CVE-2022-29034: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An error A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An error message pop up window in the web interface of the affected application does not prevent injection of JavaScript code. This could allow attackers to perform reflected cross-site scripting (XSS) attacks.
nvd
CVE-2019-19956P3HIGHCVSS 7.5fixed in 3.02019-12-24
CVE-2019-19956 [HIGH] CWE-401 CVE-2019-19956: xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
nvd
CVE-2022-32256P3MEDIUMCVSS 6.5fixed in 3.1fixed in V3.12022-06-14
CVE-2022-32256 [MEDIUM] CWE-284 CVE-2022-32256: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to low privileged users accessing privileged information.
nvd
CVE-2022-32259P3MEDIUMCVSS 6.5fixed in 3.1fixed in V3.12022-06-14
CVE-2022-32259 [MEDIUM] CWE-1244 CVE-2022-32259: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The syste A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The system images for installation or update of the affected application contain unit test scripts with sensitive information. An attacker could gain information about testing architecture and also tamper with test configuration.
nvd
CVE-2022-25313P4MEDIUMCVSS 6.5fixed in 3.12022-02-18
CVE-2022-25313 [MEDIUM] CWE-674 CVE-2022-25313: In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
nvd
CVE-2024-39869P3MEDIUMCVSS 6.5fixed in 3.2v3.2+1 more2024-07-09
CVE-2024-39869 [MEDIUM] CWE-754 CVE-2024-39869: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected products allow to upload certificates. An authenticated attacker could upload a crafted certificates leading to a permanent denial-of-service situation. In order to recover from such an attack, the offending certificate needs to be removed manuall
nvd
CVE-2021-22925P4MEDIUMCVSS 5.3fixed in 3.12021-08-05
CVE-2021-22925 [MEDIUM] CWE-200 CVE-2021-22925: curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revea
nvd
CVE-2024-39871P4MEDIUMCVSS 5.4fixed in 3.2v3.2+1 more2024-07-09
CVE-2024-39871 [MEDIUM] CWE-863 CVE-2024-39871: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly separate the rights to edit device settings and to edit settings for communication relations. This could allow an authenticated attacker with the permission to manage devices to gain access to participant groups that t
nvd
CVE-2021-37177P4MEDIUMCVSS 6.5fixed in 3.0v3.0+1 more2021-09-14
CVE-2021-37177 [MEDIUM] CWE-471 CVE-2021-37177: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The s A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The status provided by the syslog clients managed by the affected software can be manipulated by an unauthenticated attacker in the same network of the affected system.
nvd
CVE-2022-27221P4MEDIUMCVSS 5.9fixed in 3.1fixed in V3.12022-06-14
CVE-2022-27221 [MEDIUM] CWE-203 CVE-2022-27221: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An attack A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An attacker in machine-in-the-middle could obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack.
nvd
CVE-2021-37183P4MEDIUMCVSS 6.5fixed in 3.0v3.0+1 more2021-09-14
CVE-2021-37183 [MEDIUM] CWE-284 CVE-2021-37183: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The a A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software allows sending send-to-sleep notifications to the managed devices. An unauthenticated attacker in the same network of the affected system can abuse these notifications to cause a Denial-of-Service condition in the managed devices.
nvd
CVE-2022-32255P4MEDIUMCVSS 5.3fixed in 3.1fixed in V3.12022-06-14
CVE-2022-32255 [MEDIUM] CWE-284 CVE-2022-32255: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to limited information.
nvd
CVE-2016-6204P4MEDIUMCVSS 6.1≤ 1.12016-07-22
CVE-2016-6204 [MEDIUM] CWE-79 CVE-2016-6204: Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Conne Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Connect Server before 1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2025-40819P4MEDIUMCVSS 4.3fixed in 3.2v3.2+1 more2025-12-09
CVE-2025-40819 [MEDIUM] CWE-863 CVE-2025-40819: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do not properly validate license restrictions against the database, allowing direct modification of the system_ticketinfo table to bypass license limitations without proper enforcement checks. This could allow with database access to
nvd
CVE-2024-42345P4MEDIUMCVSS 4.3fixed in 3.2v3.2+1 more2024-09-10
CVE-2024-42345 [MEDIUM] CWE-384 CVE-2024-42345: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The a A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application does not properly handle user session establishment and invalidation. This could allow a remote attacker to circumvent the additional multi factor authentication for user session establishment.
nvd
CVE-2021-37193P4MEDIUMCVSS 4.3fixed in 3.0v3.0+1 more2021-09-14
CVE-2021-37193 [MEDIUM] CWE-471 CVE-2021-37193: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An un A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could manipulate certain parameters and set a valid user of the affected software as invalid (or vice-versa).
nvd
CVE-2021-22924P4LOWCVSS 3.7fixed in 3.12021-08-05
CVE-2021-22924 [LOW] CWE-20 CVE-2021-22924: libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or c
nvd
CVE-2019-13919P4MEDIUMCVSS 4.3≤ 2.0v2.02019-09-13
CVE-2019-13919 [MEDIUM] CWE-284 CVE-2019-13919: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some pages that should only be accessible by a privileged user can also be accessed by a non-privileged user. The security vulnerability could be exploited by an attacker with network access and valid credentials for the web interface. No user interaction i
nvd
Siemens Sinema Remote Connect Server vulnerabilities | cvebase