A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. This could allow an attacker with access to the backup encryption key and with the right to upload backup files to create a user with administrative privileges.
History

Mon, 09 Sep 2024 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens sinema Remote Connect Server
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:*
Vendors & Products Siemens
Siemens sinema Remote Connect Server

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2024-07-09T12:05:21.243Z

Updated: 2024-08-02T04:33:10.303Z

Reserved: 2024-07-01T13:05:40.287Z

Link: CVE-2024-39866

cve-icon Vulnrichment

Updated: 2024-08-02T04:33:10.303Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-09T12:15:17.683

Modified: 2024-09-09T15:18:08.287

Link: CVE-2024-39866

cve-icon Redhat

No data.