ID

VAR-202407-0134


CVE

CVE-2024-39873


TITLE

Siemens SINEMA Remote Connect Server has an unspecified vulnerability (CNVD-2024-31248)

Trust: 0.6

sources: CNVD: CNVD-2024-31248

DESCRIPTION

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its web API. This could allow an attacker to learn user credentials that are vulnerable to brute force attacks. The platform is mainly used for remote access, maintenance, control and diagnosis of underlying networks

Trust: 1.44

sources: NVD: CVE-2024-39873 // CNVD: CNVD-2024-31248

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2024-31248

AFFECTED PRODUCTS

vendor:siemensmodel:sinema remote connect server sp1scope:ltversion:v3.2

Trust: 0.6

sources: CNVD: CNVD-2024-31248

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2024-39873
value: HIGH

Trust: 1.0

CNVD: CNVD-2024-31248
value: HIGH

Trust: 0.6

CNVD: CNVD-2024-31248
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

productcert@siemens.com: CVE-2024-39873
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2024-31248 // NVD: CVE-2024-39873

PROBLEMTYPE DATA

problemtype:CWE-307

Trust: 1.0

sources: NVD: CVE-2024-39873

PATCH

title:Patch for Siemens SINEMA Remote Connect Server has an unspecified vulnerability (CNVD-2024-31248)url:https://www.cnvd.org.cn/patchInfo/show/567766

Trust: 0.6

sources: CNVD: CNVD-2024-31248

EXTERNAL IDS

db:NVDid:CVE-2024-39873

Trust: 1.6

db:SIEMENSid:SSA-381581

Trust: 1.6

db:CNVDid:CNVD-2024-31248

Trust: 0.6

sources: CNVD: CNVD-2024-31248 // NVD: CVE-2024-39873

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-381581.html

Trust: 1.6

sources: CNVD: CNVD-2024-31248 // NVD: CVE-2024-39873

SOURCES

db:CNVDid:CNVD-2024-31248
db:NVDid:CVE-2024-39873

LAST UPDATE DATE

2024-08-14T12:31:10.643000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2024-31248date:2024-07-10T00:00:00
db:NVDid:CVE-2024-39873date:2024-07-09T18:19:14.047

SOURCES RELEASE DATE

db:CNVDid:CNVD-2024-31248date:2024-07-11T00:00:00
db:NVDid:CVE-2024-39873date:2024-07-09T12:15:19.317