Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6w5f-rcwv-682v

Опубликовано: 09 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.3

Описание

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privilege could use this modify users outside of their own scope as well as to escalate privileges.

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privilege could use this modify users outside of their own scope as well as to escalate privileges.

EPSS

Процентиль: 47%
0.0024
Низкий

7.1 High

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-602

Связанные уязвимости

CVSS3: 6.3
nvd
больше 1 года назад

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privilege could use this modify users outside of their own scope as well as to escalate privileges.

CVSS3: 6.3
fstec
больше 1 года назад

Уязвимость сервера Siemens SINEMA Remote Connect, связанная с реализацией функций безопасности на стороне клиента, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 47%
0.0024
Низкий

7.1 High

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-602