CRITICAL🇵🇱 Wersja polska

CVE-2024-39872

CVSS 9.3v4.0pub. 2024-07-09upd. 2024-11-21

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly assign rights to temporary files created during its update process. This could allow an authenticated attacker with the 'Manage firmware updates' role to escalate their privileges on the underlying OS level.

🤖 AI Analysis
How it works

During the software update process, the application creates temporary files without properly assigning access rights (CWE-378: creation of temporary files with insecure permissions). An attacker with an account having the 'Manage firmware updates' role can manipulate these files before they are processed by the system. As a result, it is possible to obtain higher privileges at the operating system level of the host on which the application runs.

Impact

An attacker can perform privilege escalation at the operating system level, which potentially enables full takeover of the server and disruption of systems remotely managed by SINEMA Remote Connect Server.

Mitigation & patch

Siemens SINEMA Remote Connect Server must be updated to version V3.2 SP1 or newer. Detailed instructions are available in the Siemens ProductCERT security bulletin: https://cert-portal.siemens.com/productcert/html/ssa-381581.html

Who is affected

Siemens SINEMA Remote Connect Server — all versions below V3.2 SP1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Siemens Sinema Remote Connect Server

    APP
    Siemens
    3.2< 3.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product

SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego

CVE-2022-32257CRITICAL9.8PL ✓same product

Siemens SINEMA Remote Connect Server — brak kontroli dostępu prowadzący do RCE

CVE-2022-25315CRITICAL9.8PL ✓same product

Integer overflow w libexpat (storeRawNames) — RCE bez uwierzytelnienia

CVE-2022-25235CRITICAL9.8PL ✓same product

Brak walidacji kodowania UTF-8 w bibliotece Expat (libexpat)

CVE-2022-25236CRITICAL9.8PL ✓same product

Wstrzykiwanie separatorów przestrzeni nazw w Expat (libexpat) przed 2.4.5