PT-2024-5084 · Siemens · Sinema Remote Connect Server
Published
2024-07-09
·
Updated
2024-09-09
·
CVE-2024-39865
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
SINEMA Remote Connect Server versions prior to V3.2 SP1
Description:
A vulnerability has been identified in the SINEMA Remote Connect Server that allows users to upload encrypted backup files without correctly checking the path of the restored file. This could allow an attacker with access to the backup encryption key to upload malicious files, potentially leading to remote code execution. The issue is related to the unlimited upload of dangerous file types, which can be exploited by a remote attacker to execute arbitrary code using a specially crafted file.
Recommendations:
For versions prior to V3.2 SP1, update to V3.2 SP1 or later to resolve the issue. As a temporary workaround, consider restricting access to the backup file upload feature to minimize the risk of exploitation. Additionally, restrict the use of the file restoration functionality until a patch is available.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinema Remote Connect Server