First published: Thu Aug 19 2021(Updated: )
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.0 SP1). Affected devices allow to modify configuration settings over an unauthenticated channel. This could allow a local attacker to escalate privileges and execute own code on the device.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Sinema Remote Connect | <3.0 | |
Siemens Sinema Remote Connect | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-31338.
The title of this vulnerability is 'A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.0 SP1).'
The severity level of CVE-2021-31338 is high with a severity value of 7.8.
This vulnerability allows a local attacker to escalate privileges and execute their own code on the affected device.
The affected software is SINEMA Remote Connect Client versions before V3.0 SP1.
To fix this vulnerability, users should update their SINEMA Remote Connect Client to version V3.0 SP1 or higher.
You can find more information about this vulnerability in the following reference: [Siemens CERT Portal](https://cert-portal.siemens.com/productcert/pdf/ssa-816035.pdf).