CVE-2022-23102
SINEMA Remote Connect Server < V2.0 - Open Redirect
Record summary
CVE-2022-23102 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SINEMA Remote Connect ServerBrowse Siemens / SINEMA Remote Connect Server | CVE List | All versions < V2.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMSINEMA Remote Connect Server < V2.0 - Open RedirectCVSS 6.1
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to potential phishing attacks.
Remediation
Upgrade to SINEMA Remote Connect Server version 2.0 or later to fix the open redirect vulnerability.
Source: ProjectDiscovery