CVE Vulnerabilities

CVE-2024-39866

Published: Jul 09, 2024 | Modified: Sep 09, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. This could allow an attacker with access to the backup encryption key and with the right to upload backup files to create a user with administrative privileges.

Affected Software

Name Vendor Start Version End Version
Sinema_remote_connect_server Siemens * 3.2 (excluding)
Sinema_remote_connect_server Siemens 3.2 (including) 3.2 (including)
Sinema_remote_connect_server Siemens 3.2-hf1 (including) 3.2-hf1 (including)

References