A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A customized HTTP POST request could force the application to write the status of a given user to a log file, exposing sensitive user information that could provide valuable guidance to an attacker.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf | patch vendor advisory |
https://cert-portal.siemens.com/productcert/html/ssa-484086.html |