Record summary

CVE-2022-23102 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListAll versions < V2.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMSINEMA Remote Connect Server < V2.0 - Open RedirectCVSS 6.1

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to potential phishing attacks.

Remediation

Upgrade to SINEMA Remote Connect Server version 2.0 or later to fix the open redirect vulnerability.

WeaknessesCWE-601
Authorsctflearner, ritikchaddha
Template tagscvecve2022packetstormseclistsredirectsinemaauthenticatedsiemensvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
Shodan: title:"Logon - SINEMA Remote Connect"
Shodan: http.title:"logon - sinema remote connect"
FOFA: title="logon - sinema remote connect"
Google: intitle:"logon - sinema remote connect"

Source: ProjectDiscovery

References

4