ID

VAR-202407-0138


CVE

CVE-2024-39867


TITLE

Siemens SINEMA Remote Connect Server Forced Browsing Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2024-31231

DESCRIPTION

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate the authentication when performing certain actions in the web interface allowing an unauthenticated attacker to access and edit device configuration information of devices for which they have no privileges. The platform is mainly used for remote access, maintenance, control and diagnosis of underlying networks

Trust: 1.44

sources: NVD: CVE-2024-39867 // CNVD: CNVD-2024-31231

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2024-31231

AFFECTED PRODUCTS

vendor:siemensmodel:sinema remote connect server sp1scope:ltversion:v3.2

Trust: 0.6

sources: CNVD: CNVD-2024-31231

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2024-39867
value: HIGH

Trust: 1.0

CNVD: CNVD-2024-31231
value: HIGH

Trust: 0.6

CNVD: CNVD-2024-31231
severity: HIGH
baseScore: 8.0
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 8.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

productcert@siemens.com: CVE-2024-39867
baseSeverity: HIGH
baseScore: 7.6
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 4.7
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2024-31231 // NVD: CVE-2024-39867

PROBLEMTYPE DATA

problemtype:CWE-425

Trust: 1.0

sources: NVD: CVE-2024-39867

PATCH

title:Patch for Siemens SINEMA Remote Connect Server Forced Browsing Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/567761

Trust: 0.6

sources: CNVD: CNVD-2024-31231

EXTERNAL IDS

db:SIEMENSid:SSA-381581

Trust: 1.6

db:NVDid:CVE-2024-39867

Trust: 1.6

db:CNVDid:CNVD-2024-31231

Trust: 0.6

sources: CNVD: CNVD-2024-31231 // NVD: CVE-2024-39867

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-381581.html

Trust: 1.6

sources: CNVD: CNVD-2024-31231 // NVD: CVE-2024-39867

SOURCES

db:CNVDid:CNVD-2024-31231
db:NVDid:CVE-2024-39867

LAST UPDATE DATE

2024-08-14T12:52:58.562000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2024-31231date:2024-07-10T00:00:00
db:NVDid:CVE-2024-39867date:2024-07-09T18:19:14.047

SOURCES RELEASE DATE

db:CNVDid:CNVD-2024-31231date:2024-07-12T00:00:00
db:NVDid:CVE-2024-39867date:2024-07-09T12:15:17.917