Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x5gj-xmj6-c2mc

Опубликовано: 09 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 3.3

Описание

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on the server that are not properly protected allowing any user with server access to read these keys. This could allow an authenticated attacker to impersonate the server potentially enabling man-in-the-middle, traffic decryption or unauthorized access to services that trust these certificates.

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on the server that are not properly protected allowing any user with server access to read these keys. This could allow an authenticated attacker to impersonate the server potentially enabling man-in-the-middle, traffic decryption or unauthorized access to services that trust these certificates.

EPSS

Процентиль: 1%
0.0001
Низкий

3.3 Low

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 3.3
nvd
2 месяца назад

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on the server that are not properly protected allowing any user with server access to read these keys. This could allow an authenticated attacker to impersonate the server potentially enabling man-in-the-middle, traffic decryption or unauthorized access to services that trust these certificates.

CVSS3: 3.3
fstec
2 месяца назад

Уязвимость сервера Siemens SINEMA Remote Connect, связанная с неправильным присвоением разрешений для критичного ресурса, позволяющая нарушителю выполнить атаку типа «человек посередине»

EPSS

Процентиль: 1%
0.0001
Низкий

3.3 Low

CVSS3

Дефекты

CWE-732