CVE Published: 15/03/2021 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: siemens |
Vendor: Siemens |
Product: SINEMA Remote Connect Server Status : PUBLISHED
CVE-2020-25239 Description
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be changed to add a rogue server by an attacker authenticating with unprivilege user rights.