cbcvebase.

Siemens Sinema Remote Connect Server vulnerabilities

70 known vulnerabilities affecting siemens/sinema_remote_connect_server.

Total CVEs
70
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL15HIGH27MEDIUM25LOW3

Vulnerabilities

Page 4 of 4
CVE-2022-27219P4MEDIUMCVSS 4.3fixed in 3.0v3.0+1 more2022-06-14
CVE-2022-27219 [MEDIUM] CWE-358 CVE-2022-27219: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 443. This could aid attackers by making the servers more prone to clickjacking, channel downgrade attacks and other similar client-based attack vectors.
nvd
CVE-2022-27220P4MEDIUMCVSS 4.3fixed in 3.0v3.0+1 more2022-06-14
CVE-2022-27220 [MEDIUM] CWE-358 CVE-2022-27220: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 6220. This could aid attackers by making the servers more prone to clickjacking, channel downgrade attacks and other similar client-based attack vectors.
nvd
CVE-2024-39875P4MEDIUMCVSS 4.3fixed in 3.2v3.2+1 more2024-07-09
CVE-2024-39875 [MEDIUM] CWE-732 CVE-2024-39875: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The a A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows authenticated, low privilege users with the 'Manage own remote connections' permission to retrieve details about other users and group memberships.
nvd
CVE-2021-37191P4MEDIUMCVSS 4.3fixed in 3.0v3.0+1 more2021-09-14
CVE-2021-37191 [MEDIUM] CWE-799 CVE-2021-37191: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An un A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could brute force the usernames from the affected software.
nvd
CVE-2019-13920P4MEDIUMCVSS 4.3≤ 2.0v2.02019-09-13
CVE-2019-13920 [MEDIUM] CWE-352 CVE-2019-13920: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some parts of the web application are not protected against Cross Site Request Forgery (CSRF) attacks. The security vulnerability could be exploited by an attacker that is able to trigger requests of a logged-in user to the application. The vulnerability co
nvd
CVE-2021-37192P4MEDIUMCVSS 4.3fixed in 3.0v3.0+1 more2021-09-14
CVE-2021-37192 [MEDIUM] CWE-200 CVE-2021-37192: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The a A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve a list of network devices a known user can manage.
nvd
CVE-2021-37190P4MEDIUMCVSS 4.3fixed in 3.0v3.0+1 more2021-09-14
CVE-2021-37190 [MEDIUM] CWE-200 CVE-2021-37190: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The a A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve VPN connection for a known user.
nvd
CVE-2024-39876P4MEDIUMCVSS 4.0fixed in 3.2v3.2+1 more2024-07-09
CVE-2024-39876 [MEDIUM] CWE-770 CVE-2024-39876: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly handle log rotation. This could allow an unauthenticated remote attacker to cause a denial of service condition through resource exhaustion on the device.
nvd
CVE-2025-40818P4LOWCVSS 3.3fixed in 3.2v3.2+1 more2025-12-09
CVE-2025-40818 [LOW] CWE-732 CVE-2025-40818: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affec A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on the server that are not properly protected allowing any user with server access to read these keys. This could allow an authenticated attacker to impersonate the server potentially enabling man-in-the-midd
nvd
CVE-2019-13922P4LOWCVSS 2.7≤ 2.0v2.02019-09-13
CVE-2019-13922 [LOW] CWE-311 CVE-2019-13922: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An at A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administrative privileges can obtain the hash of a connected device's password. The security vulnerability could be exploited by an attacker with network access to the SINEMA Remote Connect Server and administrative privileges. At the time of
nvd
Siemens Sinema Remote Connect Server vulnerabilities | cvebase