Products
SINEMA Remote Connect Client
- < V3.2 SP2
sinema_remote_connect_client
- *
sinema_remote_connect_client
- 3
- .
- 2
Source
productcert@siemens.com
Tags
CVE-2024-42344 details
Last Modified : Sept. 10, 2024, 6:54 p.m.
Description
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive information into a log file which is readable by all legitimate users of the underlying system. This could allow an authenticated attacker to compromise the confidentiality of other users' configuration data.
CVSS Score
1 | 2 | 3 | 4 | 5.5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-532 | Insertion of Sensitive Information into Log File | Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information. |
CVSS Data
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Base Score
5.5
Exploitability Score
1.8
Impact Score
3.6
Base Severity
MEDIUM
Vector String : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
References
URL | Source |
---|---|
https://cert-portal.siemens.com/productcert/html/ssa-417159.html | productcert@siemens.com |
CPEs
Type | Vendor | Product | Version | Update | Edition | Language | Software Edition | Target Software | Target Hardware | Other Information |
---|---|---|---|---|---|---|---|---|---|---|
a | siemens | sinema_remote_connect_client | / | / | / | / | / | / | / | / |
a | siemens | sinema_remote_connect_client | 3.2 | - | / | / | / | / | / | / |
a | siemens | sinema_remote_connect_client | 3.2 | hf1 | / | / | / | / | / | / |
a | siemens | sinema_remote_connect_client | 3.2 | sp1 | / | / | / | / | / | / |