Lucene search

K
vulnrichmentSiemensVULNRICHMENT:CVE-2022-32258
HistoryJun 14, 2022 - 9:22 a.m.

CVE-2022-32258

2022-06-1409:22:10
CWE-448
siemens
github.com
5
vulnerability
sinema remote connect
server
import
device configurations
information disclosure

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

52.3%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains an older feature that allows to import device configurations via a specific endpoint. An attacker could use this vulnerability for information disclosure.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*"
    ],
    "vendor": "siemens",
    "product": "sinema_remote_connect_server",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "3.1",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

52.3%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

Related for VULNRICHMENT:CVE-2022-32258