CVE-2024-39872

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly assign rights to temporary files created during its update process. This could allow an authenticated attacker with the 'Manage firmware updates' role to escalate their privileges on the underlying OS level.
Configurations

No configuration.

History

No history.

Information

Published : 2024-07-09 12:15

Updated : 2024-07-09 18:19


NVD link : CVE-2024-39872

Mitre link : CVE-2024-39872

CVE.ORG link : CVE-2024-39872


JSON object : View

Products Affected

No product.

CWE
CWE-378

Creation of Temporary File With Insecure Permissions