---
id: CVE-2025-40819
title: >-
  A vulnerability has been identified in SINEMA Remote Connect Server (All
  versions < V3.2 SP4)
summary: >-
  A vulnerability has been identified in SINEMA Remote Connect Server (All
  versions < V3.2 SP4). Affected applications do not properly validate license
  restrictions against the database, allowing direct modification of the
  system_ticketinf…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-863
vendor: siemens
product: sinema_remote_connect_server
affected:
  - sinema_remote_connect_server < 3.2
  - sinema_remote_connect_server = 3.2
patched:
  - sinema_remote_connect_server 3.2
published: '2025-12-09'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40819'
references:
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-626856.html'
    label: productcert@siemens.com
tags:
  - nvd
epss: 0.00249
epssPercentile: 0.1479
ingestedAt: '2026-10-07T20:46:46.790Z'
---

## Overview

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do not properly validate license restrictions against the database, allowing direct modification of the system_ticketinfo table to bypass license limitations without proper enforcement checks. This could allow with database access to circumvent licensing restrictions by directly modifying database values and potentially enabling unauthorized use beyond the permitted scope.

## Affected

- `sinema_remote_connect_server < 3.2`
- `sinema_remote_connect_server = 3.2`

## Remediation

Upgrade past the affected range:

- `sinema_remote_connect_server 3.2`
