File Download Vulnerability in OZW Web Server by Siemens
CVE-2019-13941
What is CVE-2019-13941?
A vulnerability exists in the OZW Web Server, specifically in versions of OZW672 and OZW772 prior to V10.00. This flaw arises from the use of predictable path names for project files exported by authenticated users. An attacker with network access can exploit this vulnerability to download project files without the need for authentication. This poses a significant risk as it compromises the confidentiality of the system, enabling unauthorized access to potentially sensitive information. The exploit requires no user interaction, making it particularly concerning for affected systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OZW672 All versions < V10.00
OZW772 All versions < V10.00
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved