Lucene search

K
cvelistSiemensCVELIST:CVE-2022-27221
HistoryJun 14, 2022 - 9:21 a.m.

CVE-2022-27221

2022-06-1409:21:43
CWE-203
siemens
www.cve.org
5
vulnerability
sinema remote connect server
plaintext secret values
breach attack

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

47.0%

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An attacker in machine-in-the-middle could obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a “BREACH” attack.

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "SINEMA Remote Connect Server",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V3.1",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

47.0%

Related for CVELIST:CVE-2022-27221