Access Control Vulnerability in SINEMA Remote Connect Server by Siemens
CVE-2024-39871

5.4MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
9 July 2024

Summary

A security risk has been identified in the SINEMA Remote Connect Server where the application fails to properly enforce separation of permissions. An authenticated attacker with device management rights can exploit this flaw to access and modify settings pertaining to participant groups that they should not have permission to manage. This could lead to unauthorized access to sensitive configurations and control over communication relations within the system.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.