File Download Vulnerability in OZW Web Server by Siemens
CVE-2019-13941
7.5HIGH
Summary
A vulnerability exists in the OZW Web Server, specifically in versions of OZW672 and OZW772 prior to V10.00. This flaw arises from the use of predictable path names for project files exported by authenticated users. An attacker with network access can exploit this vulnerability to download project files without the need for authentication. This poses a significant risk as it compromises the confidentiality of the system, enabling unauthorized access to potentially sensitive information. The exploit requires no user interaction, making it particularly concerning for affected systems.
Affected Version(s)
OZW672 All versions < V10.00
OZW772 All versions < V10.00
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved