PT-2024-29882 · Siemens · Sinema Remote Connect Server

Published

2024-09-10

·

Updated

2024-09-10

·

CVE-2024-42345

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SINEMA Remote Connect Server versions prior to V3.2 SP2
Description A vulnerability has been identified in the SINEMA Remote Connect Server where the application does not properly handle user session establishment and invalidation. This could allow a remote attacker to circumvent the additional multi-factor authentication for user session establishment.
Recommendations For versions prior to V3.2 SP2, update to V3.2 SP2 or later to resolve the issue. As a temporary workaround, consider restricting access to the application to minimize the risk of exploitation. Avoid using the application for sensitive operations until the issue is resolved.

Fix

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2024-42345

Affected Products

Sinema Remote Connect Server