A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. As part of this backup, files can be restored without correctly checking the path of the restored file. This could allow an attacker with access to the backup encryption key to upload malicious files, that could potentially lead to remote code execution.
History

Mon, 09 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens sinema Remote Connect Server
CPEs cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:*
Vendors & Products Siemens
Siemens sinema Remote Connect Server

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2024-07-09T12:05:19.951Z

Updated: 2024-08-02T04:33:11.277Z

Reserved: 2024-07-01T13:05:40.287Z

Link: CVE-2024-39865

cve-icon Vulnrichment

Updated: 2024-08-02T04:33:11.277Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-09T12:15:17.443

Modified: 2024-09-09T15:12:08.177

Link: CVE-2024-39865

cve-icon Redhat

No data.