CVE-2024-39865

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. As part of this backup, files can be restored without correctly checking the path of the restored file. This could allow an attacker with access to the backup encryption key to upload malicious files, that could potentially lead to remote code execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:*

History

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - Patch, Vendor Advisory () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - Patch, Vendor Advisory

09 Sep 2024, 15:12

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - Patch, Vendor Advisory
Summary
  • (es) Se ha identificado una vulnerabilidad en SINEMA Remote Connect Server (todas las versiones &lt; V3.2 SP1). La aplicación afectada permite a los usuarios cargar archivos de copia de seguridad cifrados. Como parte de esta copia de seguridad, los archivos se pueden restaurar sin verificar correctamente la ruta del archivo restaurado. Esto podría permitir que un atacante con acceso a la clave de cifrado de respaldo cargue archivos maliciosos, lo que potencialmente podría conducir a la ejecución remota de código.
CPE cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
First Time Siemens sinema Remote Connect Server
Siemens

09 Jul 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 12:15

Updated : 2024-11-21 09:28


NVD link : CVE-2024-39865

Mitre link : CVE-2024-39865

CVE.ORG link : CVE-2024-39865


JSON object : View

Products Affected

siemens

  • sinema_remote_connect_server
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type