CVE-2024-39872

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly assign rights to temporary files created during its update process. This could allow an authenticated attacker with the 'Manage firmware updates' role to escalate their privileges on the underlying OS level.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:*

History

09 Sep 2024, 15:24

Type Values Removed Values Added
CPE cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
References () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - Patch, Vendor Advisory
Summary
  • (es) Se ha identificado una vulnerabilidad en SINEMA Remote Connect Server (todas las versiones &lt; V3.2 SP1). La aplicación afectada no asigna correctamente derechos a los archivos temporales creados durante su proceso de actualización. Esto podría permitir que un atacante autenticado con la función 'Manage firmware updates' escale sus privilegios en el nivel del sistema operativo subyacente.
CVSS v2 : unknown
v3 : 9.6
v2 : unknown
v3 : 9.9
CWE NVD-CWE-Other
First Time Siemens
Siemens sinema Remote Connect Server

09 Jul 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 12:15

Updated : 2024-09-09 15:24


NVD link : CVE-2024-39872

Mitre link : CVE-2024-39872

CVE.ORG link : CVE-2024-39872


JSON object : View

Products Affected

siemens

  • sinema_remote_connect_server
CWE
NVD-CWE-Other CWE-378

Creation of Temporary File With Insecure Permissions