CVE Vulnerabilities

CVE-2021-37191

Improper Control of Interaction Frequency

Published: Sep 14, 2021 | Modified: Sep 23, 2021
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
3.3 LOW
AV:A/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could brute force the usernames from the affected software.

Weakness

The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

Affected Software

Name Vendor Start Version End Version
Sinema_remote_connect_server Siemens * 3.0 (excluding)
Sinema_remote_connect_server Siemens 3.0 (including) 3.0 (including)
Sinema_remote_connect_server Siemens 3.0-sp1 (including) 3.0-sp1 (including)

References