CVE-2021-37192: Infoleak
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve a list of network devices a known user can manage.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SINEMA Remote Connect Serverto a version that resolves this vulnerability.Fixed in V3.0 SP2
Event History
Frequently Asked Questions
What is CVE-2021-37192?
CVE-2021-37192 is a vulnerability found in SINEMA Remote Connect Server (All versions < V3.0 SP2) that allows an attacker to retrieve a list of network devices a known user can manage.
How severe is CVE-2021-37192?
CVE-2021-37192 has a severity rating of medium, with a CVSS score of 4.3.
What is the affected software?
The affected software is Siemens SINEMA Remote Connect Server, with versions up to and exclusive to V3.0 SP2.
How can an attacker exploit CVE-2021-37192?
An attacker can exploit CVE-2021-37192 to retrieve a list of network devices that a known user can manage.
Is there a fix for CVE-2021-37192?
Yes, Siemens has released an update to address the vulnerability in SINEMA Remote Connect Server.