ID

VAR-202407-0146


CVE

CVE-2024-39870


TITLE

Siemens'  SINEMA Remote Connect Server  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2024-007644

DESCRIPTION

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privilege could use this modify users outside of their own scope as well as to escalate privileges. Siemens' SINEMA Remote Connect Server Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The platform is mainly used for remote access, maintenance, control and diagnosis of underlying networks

Trust: 2.16

sources: NVD: CVE-2024-39870 // JVNDB: JVNDB-2024-007644 // CNVD: CNVD-2024-31251

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2024-31251

AFFECTED PRODUCTS

vendor:siemensmodel:sinema remote connect serverscope:ltversion:3.2

Trust: 1.0

vendor:siemensmodel:sinema remote connect serverscope:eqversion:3.2

Trust: 1.0

vendor:シーメンスmodel:sinema remote connect serverscope: - version: -

Trust: 0.8

vendor:シーメンスmodel:sinema remote connect serverscope:eqversion: -

Trust: 0.8

vendor:シーメンスmodel:sinema remote connect serverscope:eqversion:3.2

Trust: 0.8

vendor:siemensmodel:sinema remote connect server sp1scope:ltversion:v3.2

Trust: 0.6

sources: CNVD: CNVD-2024-31251 // JVNDB: JVNDB-2024-007644 // NVD: CVE-2024-39870

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2024-39870
value: HIGH

Trust: 1.0

productcert@siemens.com: CVE-2024-39870
value: HIGH

Trust: 1.0

NVD: CVE-2024-39870
value: HIGH

Trust: 0.8

CNVD: CNVD-2024-31251
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2024-31251
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2024-39870
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

productcert@siemens.com: CVE-2024-39870
baseSeverity: MEDIUM
baseScore: 6.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 2.8
impactScore: 3.4
version: 3.1

Trust: 1.0

NVD: CVE-2024-39870
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2024-31251 // JVNDB: JVNDB-2024-007644 // NVD: CVE-2024-39870 // NVD: CVE-2024-39870

PROBLEMTYPE DATA

problemtype:CWE-602

Trust: 1.0

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-007644 // NVD: CVE-2024-39870

PATCH

title:Patch for Siemens SINEMA Remote Connect Server has an unspecified vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/567791

Trust: 0.6

sources: CNVD: CNVD-2024-31251

EXTERNAL IDS

db:NVDid:CVE-2024-39870

Trust: 3.2

db:SIEMENSid:SSA-381581

Trust: 2.4

db:ICS CERTid:ICSA-24-193-01

Trust: 0.8

db:JVNid:JVNVU99298639

Trust: 0.8

db:JVNDBid:JVNDB-2024-007644

Trust: 0.8

db:CNVDid:CNVD-2024-31251

Trust: 0.6

sources: CNVD: CNVD-2024-31251 // JVNDB: JVNDB-2024-007644 // NVD: CVE-2024-39870

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-381581.html

Trust: 2.4

url:https://jvn.jp/vu/jvnvu99298639/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2024-39870

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-24-193-01

Trust: 0.8

sources: CNVD: CNVD-2024-31251 // JVNDB: JVNDB-2024-007644 // NVD: CVE-2024-39870

SOURCES

db:CNVDid:CNVD-2024-31251
db:JVNDBid:JVNDB-2024-007644
db:NVDid:CVE-2024-39870

LAST UPDATE DATE

2024-09-11T21:04:49.281000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2024-31251date:2024-07-10T00:00:00
db:JVNDBid:JVNDB-2024-007644date:2024-09-10T00:49:00
db:NVDid:CVE-2024-39870date:2024-09-09T15:21:43.183

SOURCES RELEASE DATE

db:CNVDid:CNVD-2024-31251date:2024-07-11T00:00:00
db:JVNDBid:JVNDB-2024-007644date:2024-09-10T00:00:00
db:NVDid:CVE-2024-39870date:2024-07-09T12:15:18.603