VulnerabilityModified
CVE-2024-22045
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1).
MEDIUM 6.5EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information. This information is also available via the web interface of the product.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-538
- Affected
- siemens/sinema remote connect client
- Source
- productcert@siemens.com
References
- https://cert-portal.siemens.com/productcert/html/ssa-653855.htmlPatch, Vendor Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-653855.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.