Modification of assumed-immutable data in SINEMA Remote Connect Server - CVE-2021-37177

 

Modification of assumed-immutable data in SINEMA Remote Connect Server - CVE-2021-37177

Published: September 16, 2021


Vulnerability identifier: #VU56658
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37177
CWE-ID: CWE-471
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to application does not perform validation of the attacker-controlled data, assuming that data is valid and safe. A remote attacker on the local network can manipulate with the status provided by the syslog clients managed by the affected software.


Affected software

SINEMA Remote Connect Server

How to mitigate CVE-2021-37177

Install updates from vendor's website.

SINEMA Remote Connect Server - update to 3.0 SP2

External References

Related Security Bulletins