CVE-2024-42345
10.09.2024, 10:15
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application does not properly handle user session establishment and invalidation. This could allow a remote attacker to circumvent the additional multi factor authentication for user session establishment.Enginsight
Vendor | Product | Version |
---|---|---|
siemens | sinema_remote_connect_server | 𝑥 < 3.2 |
siemens | sinema_remote_connect_server | 3.2 |
siemens | sinema_remote_connect_server | 3.2:hf1 |
siemens | sinema_remote_connect_server | 3.2:sp1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration