siemens sinema-remote-connect-server CVE-2022-32257 is a vulnerability in Siemens Sinema Remote Connect Server
Published on March 12, 2024

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to resources and potentially lead to code execution.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2022-32257 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. It has the highest possible exploitability rating (3.9). The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2022-32257 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2022-32257

You can be notified by stack.watch whenever vulnerabilities like CVE-2022-32257 are published in these products:

 

What versions of Sinema Remote Connect Server are vulnerable to CVE-2022-32257?