Siemens Sinema Remote Connect Server vulnerabilities

70 known vulnerabilities affecting siemens/sinema_remote_connect_server.

Total CVEs
70
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL15HIGH28MEDIUM24LOW3

Vulnerabilities

Page 4 of 4
CVE-2020-25239HIGHCVSS 8.8fixed in 3.0vAll versions < V3.02021-03-15
CVE-2020-25239 [HIGH] CWE-863 CVE-2020-25239: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webse A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be changed to add a rogue server by an attacker authenticating with unprivilege user rights.
cvelistv5nvd
CVE-2020-25240HIGHCVSS 8.8fixed in 3.0vAll versions < V3.02021-03-15
CVE-2020-25240 [HIGH] CWE-863 CVE-2020-25240: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unprivile A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can access services when guessing the url. An attacker could impact availability, integrity and gain information from logs and templates of the service.
cvelistv5nvd
CVE-2020-7595HIGHCVSS 7.5fixed in 3.02020-01-21
CVE-2020-7595 [HIGH] CWE-835 CVE-2020-7595: xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-fi xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
nvd
CVE-2019-19956HIGHCVSS 7.5fixed in 3.02019-12-24
CVE-2019-19956 [HIGH] CWE-401 CVE-2019-19956: xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
nvd
CVE-2019-13918CRITICALCVSS 9.8fixed in 2.0v2.02019-09-13
CVE-2019-13918 [CRITICAL] CWE-307 CVE-2019-13918: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The w A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to the vulnerable software, requiring no privileges and no user interaction. The vulnerability could allow full a
nvd
CVE-2019-13919MEDIUMCVSS 4.3≤ 2.0v2.02019-09-13
CVE-2019-13919 [MEDIUM] CWE-284 CVE-2019-13919: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some pages that should only be accessible by a privileged user can also be accessed by a non-privileged user. The security vulnerability could be exploited by an attacker with network access and valid credentials for the web interface. No user interaction i
nvd
CVE-2019-13920MEDIUMCVSS 4.3≤ 2.0v2.02019-09-13
CVE-2019-13920 [MEDIUM] CWE-352 CVE-2019-13920: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some parts of the web application are not protected against Cross Site Request Forgery (CSRF) attacks. The security vulnerability could be exploited by an attacker that is able to trigger requests of a logged-in user to the application. The vulnerability co
nvd
CVE-2019-13922LOWCVSS 2.7≤ 2.0v2.02019-09-13
CVE-2019-13922 [LOW] CWE-311 CVE-2019-13922: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An at A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administrative privileges can obtain the hash of a connected device's password. The security vulnerability could be exploited by an attacker with network access to the SINEMA Remote Connect Server and administrative privileges. At the time of
nvd
CVE-2019-6570HIGHCVSS 8.8fixed in 2.0vAll versions < V2.02019-04-17
CVE-2019-6570 [HIGH] CWE-280 CVE-2019-6570: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to in A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking of user permissions, an attacker may access URLs that require special authorization. An attacker must have access to a low privileged account in order to exploit the vulnerability.
cvelistv5nvd
CVE-2016-6204MEDIUMCVSS 6.1≤ 1.12016-07-22
CVE-2016-6204 [MEDIUM] CWE-79 CVE-2016-6204: Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Conne Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Connect Server before 1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd