CVE-2022-32257

CRITICAL

SINEMA Remote Connect Server < 3.2 - Unauthenticated Improper Access Control

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to resources and potentially lead to code execution.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0035
EPSS Percentile 57.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
siemens/sinema_remote_connect_server < 3.2
Published Mar 12, 2024
Tracked Since Feb 18, 2026