CVE-2023-35796: Siemens Sinema Server
Critical severity, CVSS 9.0. EPSS: 0.6% chance of exploitation in the next 30 days.
A vulnerability has been identified in SINEMA Server V14 (All versions). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devices. An attacker with access to a monitored device could perform a stored cross-site scripting (XSS) attack that may lead to arbitrary code execution with `SYSTEM` privileges on the application server. (ZDI-CAN-19823)
Affected products
- Siemens Sinema Server: version 14.0 only
Published 2023-10-10. Last modified 2026-06-17.