A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. This could allow an attacker with access to the backup encryption key and with the right to upload backup files to create a user with administrative privileges.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-38271 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. This could allow an attacker with access to the backup encryption key and with the right to upload backup files to create a user with administrative privileges.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 02 May 2025 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 09 Sep 2024 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens sinema Remote Connect Server
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:*
Vendors & Products Siemens
Siemens sinema Remote Connect Server

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2025-08-27T20:42:56.328Z

Reserved: 2024-07-01T13:05:40.287Z

Link: CVE-2024-39866

cve-icon Vulnrichment

Updated: 2024-08-02T04:33:10.303Z

cve-icon NVD

Status : Modified

Published: 2024-07-09T12:15:17.683

Modified: 2024-11-21T09:28:27.273

Link: CVE-2024-39866

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.