PT-2024-8198 · Siemens · Sinema Remote Connect Server
Published
2024-07-09
·
Updated
2024-09-09
·
CVE-2024-39870
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
SINEMA Remote Connect Server versions prior to V3.2 SP1
Description:
A vulnerability has been identified in the SINEMA Remote Connect Server. The affected applications can be configured to allow users to manage their own users. A local authenticated user with this privilege could use this to modify users outside of their own scope as well as to escalate privileges. The vulnerability is related to the implementation of security functions on the client side, which could allow a remote attacker to elevate their privileges.
Recommendations:
For versions prior to V3.2 SP1, update to V3.2 SP1 or later to resolve the issue. As a temporary workaround, consider restricting the privilege to manage own users to minimize the risk of exploitation. Additionally, restrict access to the user management functionality to authorized personnel only.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinema Remote Connect Server