Siemens

Sinema Remote Connect Server

71 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 14.06.2022 10:15:20
  • Zuletzt bearbeitet 21.11.2024 07:06:02

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to low privileged users accessin...

  • EPSS 0.18%
  • Veröffentlicht 14.06.2022 10:15:19
  • Zuletzt bearbeitet 21.11.2024 06:55:26

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 6220. This could aid attackers by making the servers mor...

  • EPSS 0.18%
  • Veröffentlicht 14.06.2022 10:15:19
  • Zuletzt bearbeitet 21.11.2024 06:55:26

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 443. This could aid attackers by making the servers more...

  • EPSS 0.12%
  • Veröffentlicht 18.02.2022 05:15:08
  • Zuletzt bearbeitet 30.05.2025 20:15:26

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

Exploit
  • EPSS 9%
  • Veröffentlicht 18.02.2022 05:15:08
  • Zuletzt bearbeitet 05.05.2025 17:18:01

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

  • EPSS 0.32%
  • Veröffentlicht 18.02.2022 05:15:08
  • Zuletzt bearbeitet 05.05.2025 17:18:01

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

  • EPSS 10.89%
  • Veröffentlicht 16.02.2022 01:15:07
  • Zuletzt bearbeitet 05.05.2025 17:18:01

xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

  • EPSS 11.91%
  • Veröffentlicht 16.02.2022 01:15:07
  • Zuletzt bearbeitet 05.05.2025 17:18:00

xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.

Exploit
  • EPSS 4.85%
  • Veröffentlicht 09.02.2022 16:15:15
  • Zuletzt bearbeitet 21.11.2024 06:47:59

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there...

  • EPSS 3.3%
  • Veröffentlicht 26.01.2022 19:15:08
  • Zuletzt bearbeitet 05.05.2025 17:17:59

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.