CVE-2020-25239
- EPSS 0.34%
- Veröffentlicht 15.03.2021 17:15:19
- Zuletzt bearbeitet 21.11.2024 05:17:44
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be changed to add a...
CVE-2020-7595
- EPSS 0.47%
- Veröffentlicht 21.01.2020 23:15:13
- Zuletzt bearbeitet 21.11.2024 05:37:26
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
CVE-2019-19956
- EPSS 0.15%
- Veröffentlicht 24.12.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:44
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
- EPSS 0.1%
- Veröffentlicht 13.09.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:25:42
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administrative privileges can obtain the hash of a connected device's password. The security vulnerability could be exploited by an attack...
CVE-2019-13920
- EPSS 0.12%
- Veröffentlicht 13.09.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:25:42
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some parts of the web application are not protected against Cross Site Request Forgery (CSRF) attacks. The security vulnerability could be exploited by an ...
CVE-2019-13919
- EPSS 0.15%
- Veröffentlicht 13.09.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:25:41
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some pages that should only be accessible by a privileged user can also be accessed by a non-privileged user. The security vulnerability could be exploited...
CVE-2019-13918
- EPSS 0.48%
- Veröffentlicht 13.09.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:25:41
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to the vulnera...
- EPSS 0.24%
- Veröffentlicht 17.04.2019 14:29:03
- Zuletzt bearbeitet 21.11.2024 04:46:43
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking of user permissions, an attacker may access URLs that require special authorization. An attacker must have access to a low privile...
CVE-2016-6204
- EPSS 0.21%
- Veröffentlicht 22.07.2016 15:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Connect Server before 1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.