Security Vulnerability in SINEMA Remote Connect Server by Siemens
CVE-2024-39866
8.8HIGH
Summary
A vulnerability exists in the SINEMA Remote Connect Server that affects all versions prior to V3.2 SP1. This vulnerability arises from the application's handling of encrypted backup files, allowing an attacker who has access to the backup encryption key and the necessary permissions to upload such files. By exploiting this flaw, the attacker can create a user with administrative privileges, leading to a potential takeover of the server environment. Organizations using this product are encouraged to review their backup file handling procedures and apply any necessary security updates to mitigate this risk.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published