A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to low privileged users accessing privileged information.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf | patch vendor advisory |
https://cert-portal.siemens.com/productcert/html/ssa-484086.html |