A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly separate the rights to edit device settings and to edit settings for communication relations. This could allow an authenticated attacker with the permission to manage devices to gain access to participant groups that the attacked does not belong to.
History

Fri, 06 Sep 2024 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens sinema Remote Connect Server
CPEs cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:*
Vendors & Products Siemens
Siemens sinema Remote Connect Server

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2024-07-09T12:05:27.689Z

Updated: 2024-08-02T04:33:11.389Z

Reserved: 2024-07-01T13:05:40.288Z

Link: CVE-2024-39871

cve-icon Vulnrichment

Updated: 2024-08-02T04:33:11.389Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-09T12:15:18.833

Modified: 2024-09-06T18:32:01.667

Link: CVE-2024-39871

cve-icon Redhat

No data.