Denial of Service Vulnerability in SINEMA Remote Connect Server by Siemens
CVE-2024-39876

4MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
9 July 2024

Summary

A vulnerability exists in SINEMA Remote Connect Server versions prior to V3.2 SP1 due to improper log rotation handling. This flaw could be exploited by unauthenticated remote attackers to deplete system resources, leading to a denial of service condition that disrupts the availability of the device. It is crucial for affected users to apply necessary updates to mitigate potential risks.

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.