SINEMA RC Server <3.2 Access Control Bypass Exposes Resources
CVE-2022-32257 Published on March 12, 2024

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to resources and potentially lead to code execution.

NVD

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2022-32257 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2022-32257

Want to know whenever a new CVE is published for Siemens Sinema Remote Connect Server? stack.watch will email you.

 

Affected Versions

Siemens SINEMA Remote Connect Server: siemens sinema_remote_connect_server:

Exploit Probability

EPSS
0.35%
Percentile
56.83%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.