Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-32252

Опубликовано: 14 июн. 2022
Источник: nvd
CVSS3: 6.5
CVSS3: 7.8
CVSS2: 9.3
EPSS Низкий

Описание

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The application does not perform the integrity check of the update packages. Without validation, an admin user might be tricked to install a malicious package, granting root privileges to an attacker.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
Версия до 3.1 (исключая)

EPSS

Процентиль: 19%
0.00062
Низкий

6.5 Medium

CVSS3

7.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-345
CWE-345

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The application does not perform the integrity check of the update packages. Without validation, an admin user might be tricked to install a malicious package, granting root privileges to an attacker.

EPSS

Процентиль: 19%
0.00062
Низкий

6.5 Medium

CVSS3

7.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-345
CWE-345