Sinema Server
Vendor:
First CVE: Apr 19, 2014 · Active for 12 years
17
Total CVEs
More Total CVEs than 93% of tracked products
2.1
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
5.9%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Sinema Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 19, 2014
12 years ago
Most Recent CVE
Oct 10, 2023
1,020 days ago
CVE Severity & Scoring
Sinema Server17 CVEs
41%
35%
24%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (17.6%)
Network10 (58.8%)
Unknown3 (17.6%)
Physical0 (0.0%)
Adjacent Network1 (5.9%)
Attack Complexity
Low11 (64.7%)
High3 (17.6%)
Unknown3 (17.6%)
User Interaction
None13 (76.5%)
Unknown3 (17.6%)
Required1 (5.9%)
Privileges Required
Low5 (29.4%)
High2 (11.8%)
None7 (41.2%)
Unknown3 (17.6%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40438CRITICAL A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 9.0 | 97 | YES | YES |
CVE-2021-34798HIGH Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 7.5 | 61 | NO | NO |
CVE-2021-3449MEDIUM An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms | Mar 25, 2021 | 5.9 | 57 | NO | NO |
CVE-2021-39275CRITICAL ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules m | Sep 16, 2021 | 9.8 | 53 | NO | NO |
CVE-2020-25237HIGH A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). When uploading files to an affected system u | Feb 9, 2021 | 8.1 | 32 | NO | NO |
CVE-2019-10940CRITICAL A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1). Incorrect session validation could allow an attacker with a valid session, with low privil | Jan 16, 2020 | 9.9 | 30 | NO | NO |
CVE-2022-25311HIGH A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected software do not | Mar 8, 2022 | 8.8 | 27 | NO | NO |
CVE-2019-6575HIGH A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V2.7), SIMATI | Apr 17, 2019 | 7.5 | 25 | NO | NO |
CVE-2014-2731HIGH Multiple unspecified vulnerabilities in the integrated web server in Siemens SINEMA Server before 12 SP1 allow remote attackers to execute arbitrary code via HTTP traffic to port ( | Apr 19, 2014 | 9.3 | 24 | NO | NO |
CVE-2020-7580MEDIUM A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 | Jun 10, 2020 | 6.7 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
1 CVE
5.9% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.9% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Sinema Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 14.0 | 9 | 7.6 | 30.4% | 1 | 1 |