Access Control Vulnerability in SINEMA Remote Connect Server by Siemens
CVE-2024-39871
5.3MEDIUM
Summary
A security risk has been identified in the SINEMA Remote Connect Server where the application fails to properly enforce separation of permissions. An authenticated attacker with device management rights can exploit this flaw to access and modify settings pertaining to participant groups that they should not have permission to manage. This could lead to unauthorized access to sensitive configurations and control over communication relations within the system.
Affected Version(s)
SINEMA Remote Connect Server 0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published