A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly separate the rights to edit device settings and to edit settings for communication relations. This could allow an authenticated attacker with the permission to manage devices to gain access to participant groups that the attacked does not belong to.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 02 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Fri, 06 Sep 2024 19:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Siemens Siemens sinema Remote Connect Server | |
| CPEs | cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:-:*:*:*:*:*:* cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:hf1:*:*:*:*:*:* | |
| Vendors & Products | Siemens Siemens sinema Remote Connect Server | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: siemens
Published: 2024-07-09T12:05:27.689Z
Updated: 2025-08-27T20:42:57.056Z
Reserved: 2024-07-01T13:05:40.288Z
Link: CVE-2024-39871
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-02T04:33:11.389Z
 NVD
                        NVD
                    Status : Modified
Published: 2024-07-09T12:15:18.833
Modified: 2024-11-21T09:28:28.007
Link: CVE-2024-39871
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow