CVE-2021-37177: Medium severity Siemens SINEMA Remote Connect Server vulnerability
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The status provided by the syslog clients managed by the affected software can be manipulated by an unauthenticated attacker in the same network of the affected system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SINEMA Remote Connect Serverto a version that resolves this vulnerability.Fixed in V3.0 SP2
Event History
Frequently Asked Questions
What is CVE-2021-37177?
CVE-2021-37177 is a vulnerability identified in SINEMA Remote Connect Server where an unauthenticated attacker in the same network can manipulate the status provided by syslog clients.
What is the severity of CVE-2021-37177?
CVE-2021-37177 has a severity rating of 6.5 (medium).
Which versions of SINEMA Remote Connect Server are affected by CVE-2021-37177?
All versions prior to V3.0 SP2 of SINEMA Remote Connect Server are affected by CVE-2021-37177.
How can an attacker exploit CVE-2021-37177?
An attacker can exploit CVE-2021-37177 by manipulating the status provided by the syslog clients.
Is there a fix available for CVE-2021-37177?
Yes, upgrading to version V3.0 SP2 or later of SINEMA Remote Connect Server resolves the vulnerability.