CVE-2020-25239

CVE-2020-25239

Vendor Siemens
Product SINEMA Remote Connect Server
Weakness CWE-863 · Incorrect authorization
Published March 15, 2021
Last update August 4, 2024

CVSS base score

What the vulnerability does

01Description

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be changed to add a rogue server by an attacker authenticating with unprivilege user rights.

Key dates

02Disclosure timeline

March 15, 2021 CVE published
August 4, 2024 Record updated