CVE-2024-39867
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate the authentication when performing certain actions in the web interface allowing an unauthenticated attacker to access and edit device configuration information of devices for which they have no privileges.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.36%
- CWE
- CWE-425
- Published
- 2024-07-09
- Last modified
- 2026-03-13
Affected products
- Siemens SINEMA Remote Connect Server
Weakness type
Related vulnerabilities
- CVE-2026-78051 — alexta69 MeTube Cookie File cookies.txt file access
- CVE-2026-14953 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is Missing Authorization due to improper enforcement of role-based access control
- CVE-2026-76799 — code-projects Login Registration System SQL Database Backup login_registration_system.sql file access
- CVE-2026-19903 — SourceCodester Online Clothing Store SQL Database Backup shopping.sql file access
- CVE-2026-60011 — Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly...
- CVE-2026-21760 — Unauthorized Access to Admin Functionality via Forced Browsing
- CVE-2024-23573 — HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that...
- CVE-2026-13533 — agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access