CVE-2025-40819

MEDIUM

SINEMA Remote Connect Server < V3.2 SP4 - Incorrect Authorization via Database Table Modification

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do not properly validate license restrictions against the database, allowing direct modification of the system_ticketinfo table to bypass license limitations without proper enforcement checks. This could allow with database access to circumvent licensing restrictions by directly modifying database values and potentially enabling unauthorized use beyond the permitted scope.

References (1)

Core 1

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 11.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
siemens/sinema_remote_connect_server 3.2 sp1 (3 CPE variants)
siemens/sinema_remote_connect_server < 3.2
Published Dec 09, 2025
Tracked Since Feb 18, 2026