CVE-2024-39871 PUBLISHED CVSS 6.300000190734863 MEDIUM

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly separate the rights to edit device settings and to edit settings for communication relations. This could allow an authenticated attacker with the permission to manage devices to gain access to participant groups that the attacked does not belong to.

EPSS 0.17% · 38.4th percentile

Risk Scores

CVSS v3.1
6.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
EPSS Score
0.17%
38.4th percentile

Affected Products

VendorProductVersions
siemenssinema_remote_connect_server3.2, 3.2, 0
SiemensSINEMA Remote Connect Server0, 0, 0

Timeline

References

Open in Interactive Console →