Show filters
81 Total Results
Displaying 31-40 of 81
Sort by:
Attacker Value
Unknown
CVE-2022-32256
Disclosure Date: June 14, 2022 (last updated July 09, 2024)
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to low privileged users accessing privileged information.
0
Attacker Value
Unknown
CVE-2022-32255
Disclosure Date: June 14, 2022 (last updated July 09, 2024)
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to limited information.
0
Attacker Value
Unknown
CVE-2022-32254
Disclosure Date: June 14, 2022 (last updated July 09, 2024)
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A customized HTTP POST request could force the application to write the status of a given user to a log file, exposing sensitive user information that could provide valuable guidance to an attacker.
0
Attacker Value
Unknown
CVE-2022-32253
Disclosure Date: June 14, 2022 (last updated July 09, 2024)
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). Due to improper input validation, the OpenSSL certificate's password could be printed to a file reachable by an attacker.
0
Attacker Value
Unknown
CVE-2022-32252
Disclosure Date: June 14, 2022 (last updated July 09, 2024)
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The application does not perform the integrity check of the update packages. Without validation, an admin user might be tricked to install a malicious package, granting root privileges to an attacker.
0
Attacker Value
Unknown
CVE-2022-32251
Disclosure Date: June 14, 2022 (last updated July 09, 2024)
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is a missing authentication verification for a resource used to change the roles and permissions of a user. This could allow an attacker to change the permissions of any user and gain the privileges of an administrative user.
0
Attacker Value
Unknown
CVE-2022-29034
Disclosure Date: June 14, 2022 (last updated July 09, 2024)
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An error message pop up window in the web interface of the affected application does not prevent injection of JavaScript code.
This could allow attackers to perform reflected cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2022-27221
Disclosure Date: June 14, 2022 (last updated July 09, 2024)
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An attacker in machine-in-the-middle could obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack.
0
Attacker Value
Unknown
CVE-2022-27220
Disclosure Date: June 14, 2022 (last updated October 07, 2023)
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 6220. This could aid attackers by making the servers more prone to clickjacking, channel downgrade attacks and other similar client-based attack vectors.
0
Attacker Value
Unknown
CVE-2022-27219
Disclosure Date: June 14, 2022 (last updated October 07, 2023)
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 443. This could aid attackers by making the servers more prone to clickjacking, channel downgrade attacks and other similar client-based attack vectors.
0