CVE-2024-42344

Sept. 10, 2024, 6:54 p.m.

Analyzed
CVE has been recently published to the CVE List and has been received by the NVD.

Products

SINEMA Remote Connect Client

  • < V3.2 SP2

sinema_remote_connect_client

  • *

sinema_remote_connect_client

  • 3
  • .
  • 2

Source

productcert@siemens.com

Tags

CVE-2024-42344 details

Published : Sept. 10, 2024, 10:15 a.m.
Last Modified : Sept. 10, 2024, 6:54 p.m.

Description

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive information into a log file which is readable by all legitimate users of the underlying system. This could allow an authenticated attacker to compromise the confidentiality of other users' configuration data.

CVSS Score

1 2 3 4 5.5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-532 Insertion of Sensitive Information into Log File Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

CVSS Data

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

Base Score

5.5

Exploitability Score

1.8

Impact Score

3.6

Base Severity

MEDIUM

References

URL Source
https://cert-portal.siemens.com/productcert/html/ssa-417159.html productcert@siemens.com

CPEs

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
a siemens sinema_remote_connect_client / / / / / / / /
a siemens sinema_remote_connect_client 3.2 - / / / / / /
a siemens sinema_remote_connect_client 3.2 hf1 / / / / / /
a siemens sinema_remote_connect_client 3.2 sp1 / / / / / /
This website uses the NVD API, but is not approved or certified by it.