Security Vulnerability in SINEMA Remote Connect Server by Siemens
CVE-2024-39866
8.7HIGH
Summary
A vulnerability exists in the SINEMA Remote Connect Server that affects all versions prior to V3.2 SP1. This vulnerability arises from the application's handling of encrypted backup files, allowing an attacker who has access to the backup encryption key and the necessary permissions to upload such files. By exploiting this flaw, the attacker can create a user with administrative privileges, leading to a potential takeover of the server environment. Organizations using this product are encouraged to review their backup file handling procedures and apply any necessary security updates to mitigate this risk.
Affected Version(s)
SINEMA Remote Connect Server 0
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published