CVE-2020-25239: High severity siemens sinema remote connect vulnerability
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be changed to add a rogue server by an attacker authenticating with unprivilege user rights.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25239?
The severity of CVE-2020-25239 is high with a severity value of 8.8.
Which versions of SINEMA Remote Connect Server are affected by CVE-2020-25239?
All versions of SINEMA Remote Connect Server below V3.0 are affected by CVE-2020-25239.
What is the impact of CVE-2020-25239?
CVE-2020-25239 allows unauthorized actions via special URLs, potentially allowing an attacker to change the settings of the UMC authorization server.
How can an attacker exploit CVE-2020-25239?
An attacker can exploit CVE-2020-25239 by authenticating with unauthorized credentials and using special URLs to perform unauthorized actions.
Is there a fix available for CVE-2020-25239?
Siemens has released a fix for CVE-2020-25239. It is recommended to update to a version higher than V3.0.