PT-2024-8751 · Siemens · Sinema Remote Connect Server
Published
2024-07-09
·
Updated
2024-08-07
·
CVE-2024-39875
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SINEMA Remote Connect Server versions prior to V3.2 SP1
Description
The issue is related to the incorrect assignment of permissions for a critical resource in the Group Membership Handler component. This can allow a remote attacker to gain unauthorized access to protected information. The affected application allows authenticated, low-privilege users with the
Manage own remote connections permission to retrieve details about other users and group memberships.Recommendations
For versions prior to V3.2 SP1, update to version V3.2 SP1 or later to resolve the issue. As a temporary workaround, consider restricting the
Manage own remote connections permission to minimize the risk of exploitation.Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinema Remote Connect Server