CVE-2024-39866

HIGH

SINEMA Remote Connect Server <V3.2 SP1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. This could allow an attacker with access to the backup encryption key and with the right to upload backup files to create a user with administrative privileges.

Scores

CVSS v3 8.8
EPSS 0.0018
EPSS Percentile 39.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-267
Status published
Products (2)
siemens/sinema_remote_connect_server 3.2 (2 CPE variants)
siemens/sinema_remote_connect_server < 3.2
Published Jul 09, 2024
Tracked Since Feb 18, 2026