CVE-2024-39867 PUBLISHED CVSS 7.599999904632568 HIGH

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate the authentication when performing certain actions in the web interface allowing an unauthenticated attacker to access and edit device configuration information of devices for which they have no privileges.

EPSS 0.39% · 59.6th percentile

Risk Scores

CVSS v3.1
7.599999904632568
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H/E:P/RL:O/RC:C
EPSS Score
0.39%
59.6th percentile

Affected Products

VendorProductVersions
SiemensSINEMA Remote Connect Server0, 0, 0
siemenssinema_remote_connect_server0, 3.2, 3.2

Timeline

References

Open in Interactive Console →