PT-2024-8751 · Siemens · Sinema Remote Connect Server

Published

2024-07-09

·

Updated

2024-08-07

·

CVE-2024-39875

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SINEMA Remote Connect Server versions prior to V3.2 SP1
Description The issue is related to the incorrect assignment of permissions for a critical resource in the Group Membership Handler component. This can allow a remote attacker to gain unauthorized access to protected information. The affected application allows authenticated, low-privilege users with the Manage own remote connections permission to retrieve details about other users and group memberships.
Recommendations For versions prior to V3.2 SP1, update to version V3.2 SP1 or later to resolve the issue. As a temporary workaround, consider restricting the Manage own remote connections permission to minimize the risk of exploitation.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2024-10355
CVE-2024-39875

Affected Products

Sinema Remote Connect Server