First published: Tue Jun 14 2022(Updated: )
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a file upload server that is vulnerable to command injection. An attacker could use this to achieve arbitrary code execution.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SINEMA Remote Connect Server | <3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability identified in SINEMA Remote Connect Server (All versions < V3.1) is a command injection vulnerability.
The severity of CVE-2022-32262 is critical with a CVSS score of 9.8.
By exploiting the vulnerability in SINEMA Remote Connect Server, an attacker can achieve arbitrary code execution.
To fix the vulnerability in SINEMA Remote Connect Server, update the software to version 3.1 or later.
You can find more information about CVE-2022-32262 in the Siemens ProductCERT advisory at the following link: [Siemens ProductCERT Advisory](https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf).