A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading VPN configurations. This could allow an authenticated local attacker to execute arbitrary code with system privileges.
History

Thu, 21 Aug 2025 01:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:siemens:sinema_remote_connect_client:3.2:-:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2024-07-09T12:05:11.543Z

Updated: 2025-05-01T03:55:18.366Z

Reserved: 2024-06-25T15:55:17.885Z

Link: CVE-2024-39567

cve-icon Vulnrichment

Updated: 2024-07-10T13:52:56.037Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-09T12:15:16.053

Modified: 2025-08-21T00:54:46.060

Link: CVE-2024-39567

cve-icon Redhat

No data.