CVE-2024-39871

MEDIUM

SINEMA Remote Connect Server < 3.2 SP1 - Authenticated Privilege Escalation via Device Settings Misconfiguration

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly separate the rights to edit device settings and to edit settings for communication relations. This could allow an authenticated attacker with the permission to manage devices to gain access to participant groups that the attacked does not belong to.

References (1)

Core 1

Scores

CVSS v3 6.3
EPSS 0.0017
EPSS Percentile 38.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
siemens/sinema_remote_connect_server 3.2 (2 CPE variants)
siemens/sinema_remote_connect_server < 3.2
Published Jul 09, 2024
Tracked Since Feb 18, 2026