Vulnerability Details CVE-2024-39569
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading VPN configurations. This could allow an administrative remote attacker running a corresponding SINEMA Remote Connect Server to execute arbitrary code with system privileges on the client system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.9%
CVSS Severity
CVSS v3 Score 6.6
Products affected by CVE-2024-39569
-
cpe:2.3:a:siemens:sinema_remote_connect_client:-
-
cpe:2.3:a:siemens:sinema_remote_connect_client:1.0
-
cpe:2.3:a:siemens:sinema_remote_connect_client:1.3
-
cpe:2.3:a:siemens:sinema_remote_connect_client:2.0
-
cpe:2.3:a:siemens:sinema_remote_connect_client:3.1
-
cpe:2.3:a:siemens:sinema_remote_connect_client:3.2