CVE-2021-37190: Infoleak
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve VPN connection for a known user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SINEMA Remote Connect Serverto a version that resolves this vulnerability.Fixed in V3.0 SP2
Event History
Frequently Asked Questions
What is CVE-2021-37190?
CVE-2021-37190 is a vulnerability found in SINEMA Remote Connect Server (All versions < V3.0 SP2) that allows an attacker to retrieve VPN connection information for a known user.
What is the severity of CVE-2021-37190?
The severity of CVE-2021-37190 is medium, with a CVSS score of 4.3.
How does CVE-2021-37190 affect Siemens SINEMA Remote Connect Server?
CVE-2021-37190 affects Siemens SINEMA Remote Connect Server (All versions < V3.0 SP2) by exposing an information disclosure vulnerability that allows an attacker to retrieve VPN connection information.
How can I fix CVE-2021-37190?
To fix CVE-2021-37190, users should update their Siemens SINEMA Remote Connect Server to version V3.0 SP2 or newer.
Where can I find more information about CVE-2021-37190?
You can find more information about CVE-2021-37190 in the security advisory published by Siemens at the following link: [https://cert-portal.siemens.com/productcert/pdf/ssa-334944.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-334944.pdf).