A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly assign rights to temporary files created during its update process. This could allow an authenticated attacker with the 'Manage firmware updates' role to escalate their privileges on the underlying OS level.
During the software update process, the application creates temporary files without properly assigning access rights (CWE-378: creation of temporary files with insecure permissions). An attacker with an account having the 'Manage firmware updates' role can manipulate these files before they are processed by the system. As a result, it is possible to obtain higher privileges at the operating system level of the host on which the application runs.
An attacker can perform privilege escalation at the operating system level, which potentially enables full takeover of the server and disruption of systems remotely managed by SINEMA Remote Connect Server.
Siemens SINEMA Remote Connect Server must be updated to version V3.2 SP1 or newer. Detailed instructions are available in the Siemens ProductCERT security bulletin: https://cert-portal.siemens.com/productcert/html/ssa-381581.html
Siemens SINEMA Remote Connect Server — all versions below V3.2 SP1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSiemens Sinema Remote Connect Server
APPSiemens3.2< 3.2
Related vulnerabilities
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
Siemens SINEMA Remote Connect Server — brak kontroli dostępu prowadzący do RCE
Integer overflow w libexpat (storeRawNames) — RCE bez uwierzytelnienia
Brak walidacji kodowania UTF-8 w bibliotece Expat (libexpat)
Wstrzykiwanie separatorów przestrzeni nazw w Expat (libexpat) przed 2.4.5