Sinema Server

Vendor:

First CVE: Apr 19, 2014 · Active for 12 years

17
Total CVEs
More Total CVEs than 93% of tracked products
2.1
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
5.9%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Sinema Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 19, 2014
12 years ago
Most Recent CVE
Oct 10, 2023
1,020 days ago

CVE Severity & Scoring

Sinema Server17 CVEs
All CVEs352,719 CVEs
MediumHighCritical
Attack Vector
Local3 (17.6%)
Network10 (58.8%)
Unknown3 (17.6%)
Physical0 (0.0%)
Adjacent Network1 (5.9%)
Attack Complexity
Low11 (64.7%)
High3 (17.6%)
Unknown3 (17.6%)
User Interaction
None13 (76.5%)
Unknown3 (17.6%)
Required1 (5.9%)
Privileges Required
Low5 (29.4%)
High2 (11.8%)
None7 (41.2%)
Unknown3 (17.6%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20219.097YESYES
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20217.561NONO
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms
Mar 25, 20215.957NONO
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules m
Sep 16, 20219.853NONO
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). When uploading files to an affected system u
Feb 9, 20218.132NONO
A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1). Incorrect session validation could allow an attacker with a valid session, with low privil
Jan 16, 20209.930NONO
A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected software do not
Mar 8, 20228.827NONO
A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V2.7), SIMATI
Apr 17, 20197.525NONO
Multiple unspecified vulnerabilities in the integrated web server in Siemens SINEMA Server before 12 SP1 allow remote attackers to execute arbitrary code via HTTP traffic to port (
Apr 19, 20149.324NONO
A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15
Jun 10, 20206.723NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
1 CVE
5.9% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.9% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Sinema Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
14.097.630.4%11