CVE-2024-39870

MEDIUM

SINEMA Remote Connect Server <V3.2 SP1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privilege could use this modify users outside of their own scope as well as to escalate privileges.

Scores

CVSS v3 6.3
EPSS 0.0024
EPSS Percentile 47.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-602
Status published
Products (2)
siemens/sinema_remote_connect_server 3.2 (2 CPE variants)
siemens/sinema_remote_connect_server < 3.2
Published Jul 09, 2024
Tracked Since Feb 18, 2026