#VU56664 Modification of assumed-immutable data in SINEMA Remote Connect Server - CVE-2021-37193
Published: September 16, 2021
SINEMA Remote Connect Server
Siemens
Description
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to application does not perform validation of the attacker-controlled data, assuming that data is valid and safe. A remote attacker on the local network can manipulate certain parameters and set a valid user of the affected software as invalid (or vice-versa).