CVE-2024-39870: Siemens Sinema Remote Connect Server
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privilege could use this modify users outside of their own scope as well as to escalate privileges.
Affected products
- Siemens Sinema Remote Connect Server: before 3.2 (fixed in 3.2); version 3.2 only
Published 2024-07-09. Last modified 2026-06-17.