CVE-2024-39875

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows authenticated, low privilege users with the 'Manage own remote connections' permission to retrieve details about other users and group memberships.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*

History

07 Aug 2024, 19:23

Type Values Removed Values Added
First Time Siemens
Siemens sinema Remote Connect Server
References () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - () https://cert-portal.siemens.com/productcert/html/ssa-381581.html - Vendor Advisory
Summary
  • (es) Se ha identificado una vulnerabilidad en SINEMA Remote Connect Server (todas las versiones &lt; V3.2 SP1). La aplicación afectada permite a los usuarios autenticados y con privilegios bajos, con el permiso "Manage own remote connections", recuperar detalles sobre otros usuarios y membresías de grupos.
CPE cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*

09 Jul 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 12:15

Updated : 2024-08-07 19:23


NVD link : CVE-2024-39875

Mitre link : CVE-2024-39875

CVE.ORG link : CVE-2024-39875


JSON object : View

Products Affected

siemens

  • sinema_remote_connect_server
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource