A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application does not properly handle user session establishment and invalidation. This could allow a remote attacker to circumvent the additional multi factor authentication for user session establishment.
2024-09-10T10:15:12.433
2024-09-10T18:54:46.653
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | siemens | sinema_remote_connect_server | < 3.2 | Yes |
Application | siemens | sinema_remote_connect_server | 3.2 | Yes |
Application | siemens | sinema_remote_connect_server | 3.2 | Yes |
Application | siemens | sinema_remote_connect_server | 3.2 | Yes |