CVE-2024-42345: Siemens Sinema Remote Connect Server

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application does not properly handle user session establishment and invalidation. This could allow a remote attacker to circumvent the additional multi factor authentication for user session establishment.

Affected products

  • Siemens Sinema Remote Connect Server: before 3.2 (fixed in 3.2); version 3.2 only

Published 2024-09-10. Last modified 2026-06-17.