Fiche vulnérabilité
CVE-2024-39868 : faille élevée siemens sinema remote connect server (CVSS 7.3)
Description
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate the authentication when performing certain actions in the web interface allowing an unauthenticated attacker to access and edit VxLAN configuration information of networks for which they have no privileges.
En bref
- Sévérité
- Élevée (CVSS 7.3)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Exploitation active
- Non signalée par la CISA
- Publication
- 9 juil. 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- siemens sinema remote connect server