CVE-2021-37193: Medium severity Siemens SINEMA Remote Connect Server vulnerability
Published Sep 14, 2021
·Updated
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could manipulate certain parameters and set a valid user of the affected software as invalid (or vice-versa).
Affected Software
3 affected components
Siemens SINEMA Remote Connect Server<3.0
Siemens SINEMA Remote Connect Server=3.0
Siemens SINEMA Remote Connect Server=3.0-sp1
Event History
Sep 14, 2021
CVE Published
via MITRE·10:47 AM
Data Sourced
via MITRE·10:47 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-37193.
2
What is the affected software?
The affected software is Siemens SINEMA Remote Connect Server.
3
What is the severity of CVE-2021-37193?
The severity of CVE-2021-37193 is medium with a severity value of 4.3.
4
How can an attacker exploit CVE-2021-37193?
An unauthenticated attacker in the same network of the affected system could manipulate certain parameters and set a valid user of the affected software as invalid (or vice-versa).
5
Is there a fix available for CVE-2021-37193?
Yes, Siemens has released a security advisory with mitigation measures for this vulnerability.