QID 590655

Date Published: 2022-01-10

QID 590655: SINEMA Remote Connect Client Code Execution Vulnerability (SSA-816035)

SINEMA Remote Connect is a management platform for remote networks that enables the simple management of tunnel connections (VPN)

Affected Versions:
All versions Prior to V3.0 SP1(3.0.1.0)

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Successful exploitation could allow a local attacker to escalate privileges or even allow remote code execution under certain circumstances.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SSA-816035 for affected packages and patching details.

    CVEs related to QID 590655

    Software Advisories
    Advisory ID Software Component Link
    SSA-816035 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-816035.pdf