CVE-2024-39569: Command Injection
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading VPN configurations. This could allow an administrative remote attacker running a corresponding SINEMA Remote Connect Server to execute arbitrary code with system privileges on the client system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39569?
CVE-2024-39569 is considered a critical vulnerability due to its potential for remote command injection.
How do I fix CVE-2024-39569?
To mitigate CVE-2024-39569, upgrade to SINEMA Remote Connect Client version 3.2 HF1 or later.
What systems are affected by CVE-2024-39569?
CVE-2024-39569 affects all versions of Siemens SINEMA Remote Connect Client prior to 3.2 HF1.
What could an attacker do with CVE-2024-39569?
An attacker could exploit CVE-2024-39569 to execute arbitrary commands on the affected system remotely.
Is there a known exploit for CVE-2024-39569?
As of now, there are no publicly available exploits for CVE-2024-39569, but the vulnerability should be monitored closely.