Siemens
Siemens Sinema Remote Connect Server: vulnerabilidades y CVE
Siemens Sinema Remote Connect Server tiene 71 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 15 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE71
Últimos 12 meses2
Críticas15
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-40438 | Crítica (9) | 100% | ⚠ Explotación activa | 16 sept 2021 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-40819 | Media (4.3) | 0.25% | — | 9 dic 2025 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do not properly validate license restrictions against the database, allowing direct modification of… |
| CVE-2025-40818 | Baja (3.3) | 0.10% | — | 9 dic 2025 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on the server that are not properly protected allowing any user with… |
| CVE-2024-42345 | Media (5.3) | 0.34% | — | 10 sept 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application does not properly handle user session establishment and invalidation. This could allow a remote… |
| CVE-2024-39876 | Media (5.3) | 0.21% | — | 9 jul 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly handle log rotation. This could allow an unauthenticated remote attacker to cause a… |
| CVE-2024-39875 | Media (5.3) | 0.26% | — | 9 jul 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows authenticated, low privilege users with the 'Manage own remote connections' permission to… |
| CVE-2024-39874 | Alta (8.7) | 0.41% | — | 9 jul 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its Client… |
| CVE-2024-39873 | Alta (8.7) | 0.45% | — | 9 jul 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its web API. This… |
| CVE-2024-39872 | Crítica (9.3) | 0.47% | — | 9 jul 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly assign rights to temporary files created during its update process. This could… |
| CVE-2024-39871 | Media (5.3) | 0.22% | — | 9 jul 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly separate the rights to edit device settings and to edit settings for communication… |
| CVE-2024-39870 | Alta (7.1) | 0.25% | — | 9 jul 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this… |
| CVE-2024-39869 | Alta (7.1) | 0.28% | — | 9 jul 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected products allow to upload certificates. An authenticated attacker could upload a crafted certificates leading to a… |
| CVE-2024-39868 | Alta (7.2) | 0.36% | — | 9 jul 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate the authentication when performing certain actions in the web interface allowing… |
| CVE-2024-39867 | Alta (7.2) | 0.36% | — | 9 jul 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate the authentication when performing certain actions in the web interface allowing… |
| CVE-2024-39866 | Alta (8.7) | 0.24% | — | 9 jul 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. This could allow an attacker with access to the… |
| CVE-2024-39865 | Alta (8.7) | 0.45% | — | 9 jul 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. As part of this backup, files can be restored… |
| CVE-2024-39571 | Alta (8.7) | 1.3% | — | 9 jul 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to command injection due to missing server side input sanitation when loading SNMP… |
| CVE-2024-39570 | Alta (8.7) | 1.4% | — | 9 jul 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to command injection due to missing server side input sanitation when loading VxLAN… |
| CVE-2022-32257 | Crítica (9.8) | 0.84% | — | 12 mar 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead… |
| CVE-2022-32262 | Crítica (9.8) | 2.6% | — | 14 jun 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a file upload server that is vulnerable to command injection. An attacker could use this to… |
| CVE-2022-32261 | Alta (7.5) | 0.71% | — | 14 jun 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a misconfiguration in the APT update. This could allow an attacker to add insecure packages to… |
| CVE-2022-32260 | Crítica (9.8) | 0.75% | — | 14 jun 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application creates temporary user credentials for UMC (User Management Component) users. An attacker could use… |
| CVE-2022-32259 | Media (6.5) | 0.63% | — | 14 jun 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The system images for installation or update of the affected application contain unit test scripts with sensitive information.… |
| CVE-2022-32258 | Alta (7.5) | 0.87% | — | 14 jun 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains an older feature that allows to import device configurations via a specific endpoint. An… |
| CVE-2022-32256 | Media (6.5) | 0.66% | — | 14 jun 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead… |
| CVE-2022-32255 | Media (5.3) | 0.81% | — | 14 jun 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead… |
| CVE-2022-32254 | Alta (7.5) | 0.83% | — | 14 jun 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A customized HTTP POST request could force the application to write the status of a given user to a log file, exposing sensitive… |
| CVE-2022-32253 | Alta (7.5) | 0.60% | — | 14 jun 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). Due to improper input validation, the OpenSSL certificate's password could be printed to a file reachable by an attacker. |
| CVE-2022-32252 | Alta (7.8) | 0.35% | — | 14 jun 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The application does not perform the integrity check of the update packages. Without validation, an admin user might be tricked… |
| CVE-2022-32251 | Crítica (9.8) | 1.2% | — | 14 jun 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is a missing authentication verification for a resource used to change the roles and permissions of a user. This could… |
| CVE-2022-29034 | Media (6.1) | 29% | — | 14 jun 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An error message pop up window in the web interface of the affected application does not prevent injection of JavaScript code.… |