Access Control Vulnerability in SINEMA Remote Connect Server by Siemens
CVE-2024-39871
5.4MEDIUM
Summary
A security risk has been identified in the SINEMA Remote Connect Server where the application fails to properly enforce separation of permissions. An authenticated attacker with device management rights can exploit this flaw to access and modify settings pertaining to participant groups that they should not have permission to manage. This could lead to unauthorized access to sensitive configurations and control over communication relations within the system.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published