CVE-2025-40819: Medium severity Siemens SINEMA Remote Connect Server vulnerability
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do not properly validate license restrictions against the database, allowing direct modification of the systemticketinfo table to bypass license limitations without proper enforcement checks. This could allow with database access to circumvent licensing restrictions by directly modifying database values and potentially enabling unauthorized use beyond the permitted scope.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40819?
The severity of CVE-2025-40819 is classified as high due to the potential for unauthorized modification of the system_ticketinfo table.
How do I fix CVE-2025-40819?
To fix CVE-2025-40819, update the SINEMA Remote Connect Server to version 3.2 SP4 or later.
What systems are affected by CVE-2025-40819?
CVE-2025-40819 affects all versions of SINEMA Remote Connect Server prior to version 3.2 SP4.
What risk does CVE-2025-40819 pose to organizations?
CVE-2025-40819 poses a risk of bypassing license restrictions, potentially leading to unauthorized access and misuse of the application.
Is there a workaround for CVE-2025-40819?
There is no official workaround for CVE-2025-40819; upgrading to the latest version is recommended.