A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains an older feature that allows to import device configurations via a specific endpoint. An attacker could use this vulnerability for information disclosure.
A UI function is obsolete and the product does not warn the user.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf | patch vendor advisory |
https://cert-portal.siemens.com/productcert/html/ssa-484086.html |