CVE-2024-39870

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privilege could use this modify users outside of their own scope as well as to escalate privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:*

History

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - Patch, Vendor Advisory () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 6.3

09 Sep 2024, 15:21

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en SINEMA Remote Connect Server (todas las versiones &lt; V3.2 SP1). Las aplicaciones afectadas se pueden configurar para permitir a los usuarios administrar sus propios usuarios. Un usuario autenticado local con este privilegio podría utilizar esto para modificar usuarios fuera de su propio alcance, así como para escalar privilegios.
CVSS v2 : unknown
v3 : 6.3
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
References () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - Patch, Vendor Advisory
First Time Siemens sinema Remote Connect Server
Siemens
CWE NVD-CWE-noinfo

09 Jul 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 12:15

Updated : 2024-11-21 09:28


NVD link : CVE-2024-39870

Mitre link : CVE-2024-39870

CVE.ORG link : CVE-2024-39870


JSON object : View

Products Affected

siemens

  • sinema_remote_connect_server
CWE
CWE-602

Client-Side Enforcement of Server-Side Security

NVD-CWE-noinfo