Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-27220

Опубликовано: 14 июн. 2022
Источник: nvd
CVSS3: 4.3
CVSS2: 4.3
EPSS Низкий

Описание

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 6220. This could aid attackers by making the servers more prone to clickjacking, channel downgrade attacks and other similar client-based attack vectors.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
Версия до 3.0 (исключая)
cpe:2.3:a:siemens:sinema_remote_connect_server:3.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.0:sp1:*:*:*:*:*:*

EPSS

Процентиль: 39%
0.00177
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-358
CWE-1021

Связанные уязвимости

CVSS3: 4.3
github
больше 3 лет назад

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 6220. This could aid attackers by making the servers more prone to clickjacking, channel downgrade attacks and other similar client-based attack vectors.

EPSS

Процентиль: 39%
0.00177
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-358
CWE-1021