CVE-2022-29034: XSS
Published Jun 14, 2022
·Updated
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An error message pop up window in the web interface of the affected application does not prevent injection of JavaScript code. This could allow attackers to perform reflected cross-site scripting (XSS) attacks.
Affected Software
1 affected component
Siemens SINEMA Remote Connect Server<3.1
Remediation
Event History
Jun 14, 2022
CVE Published
via MITRE·09:21 AM
Data Sourced
via MITRE·09:21 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this SINEMA Remote Connect Server vulnerability?
The vulnerability ID for this SINEMA Remote Connect Server vulnerability is CVE-2022-29034.
2
What is the severity rating of CVE-2022-29034?
The severity rating of CVE-2022-29034 is medium with a CVSS score of 6.1.
3
What is the affected version of SINEMA Remote Connect Server?
All versions prior to V3.1 are affected by this vulnerability.
4
What is the impact of this vulnerability?
This vulnerability allows attackers to perform reflected cross-site scripting (XSS) attacks.
5
How can I fix CVE-2022-29034 in SINEMA Remote Connect Server?
To fix CVE-2022-29034, it is recommended to update SINEMA Remote Connect Server to version 3.1 or higher.