Vulnerability CVE-2024-39870


Published: 2024-07-09

Description:
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privilege could use this modify users outside of their own scope as well as to escalate privileges.

Type:

CWE-602

(Client-Side Enforcement of Server-Side Security)

 References:
https://cert-portal.siemens.com/productcert/html/ssa-381581.html

Copyright 2025, cxsecurity.com

 

Back to Top