CVE Vulnerabilities

CVE-2024-39870

Published: Jul 09, 2024 | Modified: Sep 09, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privilege could use this modify users outside of their own scope as well as to escalate privileges.

Affected Software

Name Vendor Start Version End Version
Sinema_remote_connect_server Siemens * 3.2 (excluding)
Sinema_remote_connect_server Siemens 3.2 (including) 3.2 (including)
Sinema_remote_connect_server Siemens 3.2-hf1 (including) 3.2-hf1 (including)

References