Vulnerabilities > Siemens > Sinema Remote Connect Server

DATE CVE VULNERABILITY TITLE RISK
2021-03-15 CVE-2020-25239 Incorrect Authorization vulnerability in Siemens Sinema Remote Connect Server
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0).
network
low complexity
siemens CWE-863
8.8
2020-01-21 CVE-2020-7595 Infinite Loop vulnerability in multiple products
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
7.5
2019-12-24 CVE-2019-19956 Memory Leak vulnerability in multiple products
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
7.5
2019-09-13 CVE-2019-13922 Missing Encryption of Sensitive Data vulnerability in Siemens Sinema Remote Connect Server 2.0
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1).
network
low complexity
siemens CWE-311
2.7
2019-09-13 CVE-2019-13920 Cross-Site Request Forgery (CSRF) vulnerability in Siemens Sinema Remote Connect Server 2.0
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1).
network
low complexity
siemens CWE-352
4.3
2019-09-13 CVE-2019-13919 Unspecified vulnerability in Siemens Sinema Remote Connect Server 2.0
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1).
network
low complexity
siemens
4.3
2019-09-13 CVE-2019-13918 Weak Password Requirements vulnerability in Siemens Sinema Remote Connect Server 2.0
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1).
network
low complexity
siemens CWE-521
critical
9.8
2019-04-17 CVE-2019-6570 Improper Handling of Insufficient Permissions or Privileges vulnerability in Siemens Sinema Remote Connect Server
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0).
network
low complexity
siemens CWE-280
8.8
2016-07-22 CVE-2016-6204 Cross-site Scripting vulnerability in Siemens Sinema Remote Connect Server 1.0/1.1
Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Connect Server before 1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
network
low complexity
siemens CWE-79
6.1