CVE-2024-39866: High severity siemens sinema remote connect vulnerability
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. This could allow an attacker with access to the backup encryption key and with the right to upload backup files to create a user with administrative privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39866?
CVE-2024-39866 is considered a high severity vulnerability due to its potential to allow unauthorized user creation through uploaded backup files.
How do I fix CVE-2024-39866?
To mitigate CVE-2024-39866, upgrade to SINEMA Remote Connect Server version 3.2 SP1 or later.
Who is affected by CVE-2024-39866?
CVE-2024-39866 affects all versions of SINEMA Remote Connect Server prior to 3.2 SP1.
What does CVE-2024-39866 allow an attacker to do?
CVE-2024-39866 allows an attacker with access to the backup encryption key to create unauthorized users by uploading manipulated backup files.
Is there a workaround for CVE-2024-39866?
There are no official workarounds for CVE-2024-39866; upgrading to a patched version is recommended.