#VU97147 Session Fixation in SINEMA Remote Connect Server - CVE-2024-42345
Published: September 11, 2024 / Updated: September 16, 2024
SINEMA Remote Connect Server
Siemens
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected application does not properly handle user session establishment and invalidation. A remote user can circumvent the additional multi factor authentication for user session establishment.