Command Injection Vulnerability in SINEMA Remote Connect Server by Siemens
CVE-2022-32262
8.8HIGH
Summary
A command injection vulnerability exists in SINEMA Remote Connect Server, affecting all versions prior to 3.1. The application contains a file upload server that allows attackers to exploit this vulnerability, potentially leading to arbitrary code execution. If successfully executed, this could allow unauthorized users to execute malicious commands on the server, posing serious risks to data integrity and system security.
Affected Version(s)
SINEMA Remote Connect Server 0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved