VYPR

Sinema Remote Connect Server

by Siemens Foundation

CVEs (81)

  • CVE-2016-6204MedJul 22, 2016
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Connect Server before 1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

  • CVE-2022-27221MedJun 14, 2022
    risk 0.38cvss 5.9epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An attacker in machine-in-the-middle could obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially…

  • CVE-2022-32261MedJun 14, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a misconfiguration in the APT update. This could allow an attacker to add insecure packages to the application.

  • CVE-2022-32258MedJun 14, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains an older feature that allows to import device configurations via a specific endpoint. An attacker could use this vulnerability for information disclosure.

  • CVE-2022-32255MedJun 14, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to limited information.

  • CVE-2022-32253MedJun 14, 2022
    risk 0.32cvss 4.9epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). Due to improper input validation, the OpenSSL certificate's password could be printed to a file reachable by an attacker.

  • CVE-2024-42344MedSep 10, 2024
    risk 0.29cvss 4.4epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive information into a log file which is readable by all legitimate users of the underlying system. This could allow an authenticated attacker to…

  • CVE-2025-40819MedDec 9, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do not properly validate license restrictions against the database, allowing direct modification of the system_ticketinfo table to bypass license limitations…

  • CVE-2024-42345MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application does not properly handle user session establishment and invalidation. This could allow a remote attacker to circumvent the additional multi factor…

  • CVE-2024-32006MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application does not expire the user session on reboot without logout. This could allow an attacker to bypass Multi-Factor Authentication.

  • CVE-2024-39875MedJul 9, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows authenticated, low privilege users with the 'Manage own remote connections' permission to retrieve details about other users and group memberships.

  • CVE-2022-32256MedJun 14, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to low privileged users accessing privileged information.

  • CVE-2022-32254MedJun 14, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A customized HTTP POST request could force the application to write the status of a given user to a log file, exposing sensitive user information that could provide valuable guidance to an…

  • CVE-2022-27220MedJun 14, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 6220. This could aid attackers by making the servers more prone to clickjacking,…

  • CVE-2022-27219MedJun 14, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 443. This could aid attackers by making the servers more prone to clickjacking,…

  • CVE-2021-37193MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could manipulate certain parameters and set a valid user of the affected software as invalid (or vice-versa).

  • CVE-2021-37192MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve a list of network devices a known user can manage.

  • CVE-2021-37191MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could brute force the usernames from the affected software.

  • CVE-2021-37190MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve VPN connection for a known user.

  • CVE-2021-22925MedAug 5, 2021
    risk 0.28cvss 5.3epss 0.05

    curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized…