CVE-2024-39868: High severity siemens sinema remote connect vulnerability
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate the authentication when performing certain actions in the web interface allowing an unauthenticated attacker to access and edit VxLAN configuration information of networks for which they have no privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39868?
The severity of CVE-2024-39868 is considered high due to unauthorized access to VxLAN configuration.
How do I fix CVE-2024-39868?
To fix CVE-2024-39868, upgrade to SINEMA Remote Connect Server version 3.2 SP1 or higher.
What types of actions can be exploited in CVE-2024-39868?
CVE-2024-39868 can be exploited to access and modify VxLAN configuration without authentication.
Who is affected by CVE-2024-39868?
CVE-2024-39868 affects all versions of SINEMA Remote Connect Server prior to version 3.2 SP1.
Is there a workaround for CVE-2024-39868 before patching?
There is no official workaround for CVE-2024-39868 recommended other than upgrading the software.