### [CVE-2022-23102](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23102) ![](https://img.shields.io/static/v1?label=Product&message=SINEMA%20Remote%20Connect%20Server&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-601%3A%20URL%20Redirection%20to%20Untrusted%20Site%20('Open%20Redirect')&color=brighgreen) ### Description A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks. ### POC #### Reference - http://packetstormsecurity.com/files/165966/SIEMENS-SINEMA-Remote-Connect-1.0-SP3-HF1-Open-Redirection.html - http://packetstormsecurity.com/files/165966/SIEMENS-SINEMA-Remote-Connect-1.0-SP3-HF1-Open-Redirection.html - http://seclists.org/fulldisclosure/2022/Feb/20 - http://seclists.org/fulldisclosure/2022/Feb/20 #### Github - https://github.com/ARPSyndicate/cvemon