CVE-2020-25239: Siemens Sinema Remote Connect Server

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be changed to add a rogue server by an attacker authenticating with unprivilege user rights.

Affected products

  • Siemens Sinema Remote Connect Server: before 3.0 (fixed in 3.0)

Published 2021-03-15. Last modified 2026-06-17.