CVE-2025-40819
MEDIUMDescription
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do not properly validate license restrictions against the database, allowing direct modification of the system_ticketinfo table to bypass license limitations without proper enforcement checks. This could allow with database access to circumvent licensing restrictions by directly modifying database values and potentially enabling unauthorized use beyond the permitted scope.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| siemens | sinema_remote_connect_server |
| siemens | sinema_remote_connect_server |
| siemens | sinema_remote_connect_server |
| siemens | sinema_remote_connect_server |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-40819? +
How severe is CVE-2025-40819? +
What products are affected by CVE-2025-40819? +
How do I check if I'm vulnerable to CVE-2025-40819? +
Related Vulnerabilities
authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with at …
Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to …
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently …
Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 …
RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using …
A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default …