CVE-2024-39872

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly assign rights to temporary files created during its update process. This could allow an authenticated attacker with the 'Manage firmware updates' role to escalate their privileges on the underlying OS level.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:*

History

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - Patch, Vendor Advisory () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 9.9
v2 : unknown
v3 : 9.6

09 Sep 2024, 15:24

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en SINEMA Remote Connect Server (todas las versiones &lt; V3.2 SP1). La aplicación afectada no asigna correctamente derechos a los archivos temporales creados durante su proceso de actualización. Esto podría permitir que un atacante autenticado con la función 'Manage firmware updates' escale sus privilegios en el nivel del sistema operativo subyacente.
CPE cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
References () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - Patch, Vendor Advisory
First Time Siemens
Siemens sinema Remote Connect Server
CVSS v2 : unknown
v3 : 9.6
v2 : unknown
v3 : 9.9
CWE NVD-CWE-Other

09 Jul 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 12:15

Updated : 2024-11-21 09:28


NVD link : CVE-2024-39872

Mitre link : CVE-2024-39872

CVE.ORG link : CVE-2024-39872


JSON object : View

Products Affected

siemens

  • sinema_remote_connect_server
CWE
CWE-378

Creation of Temporary File With Insecure Permissions

NVD-CWE-Other