Known Vulnerabilities for Sinema Server by Siemens
Listed below are 10 of the newest known vulnerabilities associated with "Sinema Server" by "Siemens".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
More device details and information can be found at device.report here: Siemens Sinema Server
Known Vulnerabilities
CVE | Shortened Description | Severity | Publish Date | Last Modified |
---|---|---|---|---|
CVE-2021-40438 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This is... | 9 - CRITICAL | 2021-09-16 | 2022-10-05 |
CVE-2021-39275 | ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data t... | 9.8 - CRITICAL | 2021-09-16 | 2022-10-05 |
CVE-2021-34798 | Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earli... | 7.5 - HIGH | 2021-09-16 | 2022-10-28 |
CVE-2021-3449 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 r... | 5.9 - MEDIUM | 2021-03-25 | 2022-08-29 |
CVE-2020-25237 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 ... | 8.1 - HIGH | 2021-02-09 | 2021-03-10 |
CVE-2020-7580 | A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All vers... | 6.7 - MEDIUM | 2020-06-10 | 2023-04-28 |
CVE-2019-10941 | A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that ... | 5.3 - MEDIUM | 2021-09-14 | 2021-09-23 |
CVE-2019-10940 | A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1). Incorrect session validation could ... | 9.9 - CRITICAL | 2020-01-16 | 2021-09-20 |
CVE-2019-6575 | A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC... | 7.5 - HIGH | 2019-04-17 | 2022-10-06 |
CVE-2017-6865 | A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC Automation Tool (All versi... | 6.5 - MEDIUM | 2017-05-11 | 2019-03-21 |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Siemens | Sinema Server | 12.0 | - | All | All |
Application | Siemens | Sinema Server | 12.0 | sp1 | All | All |
Hardware | Siemens | Sinema Server | - | All | All | All |
Popular searches for Sinema Server
Siemens SINEMA Server | CISA

Siemens SINEMA Server | CISA h f d1. EXECUTIVE SUMMARY CVSS v3 9.9 ATTENTION: Exploitable remotely/low skill level to exploit Vendor: Siemens Equipment: SINEMA Server Vulnerability: Incorrect Privilege Assignment 2. RISK EVALUATION Successful exploitation of this vulnerability could allow an attacker with a valid session, with low privileges, to perform firmware updates and other administrative operations on connected devices.
Siemens Server (computing) Vulnerability (computing) ISACA Exploit (computer security) Website Smart device Patch (computing) Principle of least privilege User (computing) Computer security RISKS Digest Common Vulnerability Scoring System Virtual private network Security hacker Session (computer science) Industrial control system Vulnerability management Product (business) CertiorariSiemens SINEMA Remote Connect Server | CISA

Siemens SINEMA Remote Connect Server | CISA M K I1. EXECUTIVE SUMMARY CVSS v3 8.1 ATTENTION: Exploitable remotely Vendor: Siemens Equipment: SINEMA Remote Connect Server Vulnerabilities: Improper Restriction of Excessive Authentication Attempts, Information Exposure, Cross-Site Request Forgery, Use of Password Hash with Insufficient Computational Effort 2.
Siemens Server (computing) Vulnerability (computing) Common Vulnerability Scoring System ISACA Website Cross-site request forgery User interface Password Authentication User (computing) Exploit (computer security) Hash function Information Common Vulnerabilities and Exposures Adobe Connect String (computer science) Security hacker Certiorari Antivirus software