Lucene search

K
nvd[email protected]NVD:CVE-2024-42344
HistorySep 10, 2024 - 10:15 a.m.

CVE-2024-42344

2024-09-1010:15:12
CWE-532
web.nvd.nist.gov
3
vulnerability
sinema remote connect
confidentiality
log file

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

9.6%

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive information into a log file which is readable by all legitimate users of the underlying system. This could allow an authenticated attacker to compromise the confidentiality of other users’ configuration data.

Affected configurations

Nvd
Node
siemenssinema_remote_connect_clientRange<3.2
OR
siemenssinema_remote_connect_clientMatch3.2-
OR
siemenssinema_remote_connect_clientMatch3.2hf1
OR
siemenssinema_remote_connect_clientMatch3.2sp1
VendorProductVersionCPE
siemenssinema_remote_connect_client*cpe:2.3:a:siemens:sinema_remote_connect_client:*:*:*:*:*:*:*:*
siemenssinema_remote_connect_client3.2cpe:2.3:a:siemens:sinema_remote_connect_client:3.2:-:*:*:*:*:*:*
siemenssinema_remote_connect_client3.2cpe:2.3:a:siemens:sinema_remote_connect_client:3.2:hf1:*:*:*:*:*:*
siemenssinema_remote_connect_client3.2cpe:2.3:a:siemens:sinema_remote_connect_client:3.2:sp1:*:*:*:*:*:*

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

9.6%

Related for NVD:CVE-2024-42344