CVE-2024-39870

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privilege could use this modify users outside of their own scope as well as to escalate privileges.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:*

History

09 Sep 2024, 15:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.3
v2 : unknown
v3 : 7.8
First Time Siemens
Siemens sinema Remote Connect Server
References () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - Patch, Vendor Advisory
Summary
  • (es) Se ha identificado una vulnerabilidad en SINEMA Remote Connect Server (todas las versiones &lt; V3.2 SP1). Las aplicaciones afectadas se pueden configurar para permitir a los usuarios administrar sus propios usuarios. Un usuario autenticado local con este privilegio podría utilizar esto para modificar usuarios fuera de su propio alcance, así como para escalar privilegios.
CPE cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:*
CWE NVD-CWE-noinfo

09 Jul 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 12:15

Updated : 2024-09-09 15:21


NVD link : CVE-2024-39870

Mitre link : CVE-2024-39870

CVE.ORG link : CVE-2024-39870


JSON object : View

Products Affected

siemens

  • sinema_remote_connect_server
CWE
NVD-CWE-noinfo CWE-602

Client-Side Enforcement of Server-Side Security