📦 Sinema Remote Connect Server

by Siemens

🔍 What is Sinema Remote Connect Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-39872

CRITICAL CVSS 9.6 Jul 9, 2024

A privilege escalation vulnerability in SINEMA Remote Connect Server allows authenticated attackers with 'Manage firmware updates' role to gain OS-level privileges through improper temporary file perm...

CVE-2022-32257

CRITICAL CVSS 9.8 Mar 12, 2024

SINEMA Remote Connect Server versions before V3.2 have improper access control on web service endpoints, allowing attackers to bypass authentication and access restricted resources. This could lead to...

CVE-2022-25315

CRITICAL CVSS 9.8 Feb 18, 2022

CVE-2022-25315 is an integer overflow vulnerability in Expat's storeRawNames function that can lead to heap buffer overflow. This allows attackers to potentially execute arbitrary code or cause denial...

CVE-2022-25235

CRITICAL CVSS 9.8 Feb 16, 2022

CVE-2022-25235 is a critical vulnerability in Expat (libexpat) XML parser where improper UTF-8 character validation allows attackers to bypass security checks. This affects any application using vulne...

CVE-2022-23852

CRITICAL CVSS 9.8 Jan 24, 2022

CVE-2022-23852 is a signed integer overflow vulnerability in Expat (libexpat) XML parser that can lead to buffer overflow. When XML_CONTEXT_BYTES is configured to a nonzero value, XML_GetBuffer can ov...

CVE-2022-22822

CRITICAL CVSS 9.8 Jan 10, 2022

CVE-2022-22822 is an integer overflow vulnerability in Expat's XML parser that can lead to heap buffer overflow. This allows attackers to execute arbitrary code or cause denial of service by processin...

CVE-2022-22824

CRITICAL CVSS 9.8 Jan 10, 2022

CVE-2022-22824 is an integer overflow vulnerability in Expat's defineAttribute function in xmlparse.c. This allows attackers to cause heap-based buffer overflows, potentially leading to arbitrary code...

CVE-2021-20093

CRITICAL CVSS 9.1 Jun 16, 2021

CVE-2021-20093 is a buffer over-read vulnerability in Wibu-Systems CodeMeter that allows unauthenticated remote attackers to read heap memory contents or cause denial of service. This affects CodeMete...

CVE-2024-39874

HIGH CVSS 7.5 Jul 9, 2024

SINEMA Remote Connect Server versions before V3.2 SP1 lack proper brute force protection in the Client Communication component, allowing attackers to guess user credentials through repeated login atte...

CVE-2024-39868

HIGH CVSS 7.6 Jul 9, 2024

An authentication bypass vulnerability in SINEMA Remote Connect Server allows unauthenticated attackers to access and modify VxLAN network configurations without proper authorization. This affects all...

CVE-2024-39866

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SINEMA Remote Connect Server allows attackers with access to the backup encryption key and upload permissions to create administrative users by uploading manipulated backup files...

CVE-2024-39570

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability allows authenticated attackers to execute arbitrary commands with root privileges on SINEMA Remote Connect Server by exploiting insufficient input validation in VxLAN configuration ...

CVE-2022-32262

HIGH CVSS 8.8 Jun 14, 2022

CVE-2022-32262 is a command injection vulnerability in SINEMA Remote Connect Server that allows attackers to execute arbitrary code through a vulnerable file upload server. This affects all versions b...

CVE-2022-32251

HIGH CVSS 8.8 Jun 14, 2022

CVE-2022-32251 is an authentication bypass vulnerability in Siemens SINEMA Remote Connect Server that allows attackers to modify user permissions without authentication. This enables privilege escalat...

CVE-2022-25314

HIGH CVSS 7.5 Feb 18, 2022

CVE-2022-25314 is an integer overflow vulnerability in Expat's copyString function that can lead to heap buffer overflow. This allows attackers to potentially execute arbitrary code or cause denial of...

CVE-2022-23990

HIGH CVSS 7.5 Jan 26, 2022

CVE-2022-23990 is an integer overflow vulnerability in Expat (libexpat) XML parser library that can lead to denial of service or arbitrary code execution. Any application using vulnerable versions of ...

CVE-2022-22826

HIGH CVSS 8.8 Jan 10, 2022

CVE-2022-22826 is an integer overflow vulnerability in Expat's XML parser that can lead to heap memory corruption. Attackers can exploit this by providing specially crafted XML input, potentially caus...

CVE-2021-46143

HIGH CVSS 8.1 Jan 6, 2022

CVE-2021-46143 is an integer overflow vulnerability in Expat's XML parser that can lead to heap memory corruption. Attackers can exploit this by providing specially crafted XML input, potentially caus...

CVE-2020-25239

HIGH CVSS 8.8 Mar 15, 2021

CVE-2020-25239 is an authorization bypass vulnerability in Siemens SINEMA Remote Connect Server that allows unprivileged users to modify UMC authorization server settings via specially crafted URLs. T...

CVE-2025-40819

MEDIUM CVSS 4.3 Dec 9, 2025

This vulnerability in SINEMA Remote Connect Server allows attackers with database access to directly modify the system_ticketinfo table and bypass license restrictions. This could enable unauthorized ...

CVE-2024-39876

MEDIUM CVSS 4.0 Jul 9, 2024

A log rotation vulnerability in SINEMA Remote Connect Server allows unauthenticated remote attackers to cause denial of service through resource exhaustion. All versions before V3.2 SP1 are affected. ...

CVE-2024-39870

MEDIUM CVSS 6.3 Jul 9, 2024

A privilege escalation vulnerability in SINEMA Remote Connect Server allows authenticated local users with self-management privileges to modify users outside their authorized scope and elevate their p...

CVE-2025-40818

LOW CVSS 3.3 Dec 9, 2025

SINEMA Remote Connect Server versions before V3.2 SP4 store SSL/TLS private keys with insufficient protection, allowing any authenticated user with server access to read them. This enables attackers t...