PT-2022-21184 · Siemens · Sinema Remote Connect Server

CVE-2022-32259

·

Published

2022-06-14

·

Updated

2024-07-09

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SINEMA Remote Connect Server versions prior to V3.1
Description A vulnerability has been identified where system images for installation or update of the affected application contain unit test scripts with sensitive information. An attacker could gain information about testing architecture and also tamper with test configuration.
Recommendations For versions prior to V3.1, update to version V3.1 or later to resolve the issue. As a temporary workaround, consider removing or securing the unit test scripts from the system images to prevent information disclosure and tampering. Restrict access to the system images and the affected application to minimize the risk of exploitation.

Fix

Unsafe Debug Access Level

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-32259

Affected Products

Sinema Remote Connect Server