File Download Vulnerability in OZW Web Server by Siemens
CVE-2019-13941

7.5HIGH

Key Information:

Vendor

Siemens Ag

Vendor
CVE Published:
11 February 2020

What is CVE-2019-13941?

A vulnerability exists in the OZW Web Server, specifically in versions of OZW672 and OZW772 prior to V10.00. This flaw arises from the use of predictable path names for project files exported by authenticated users. An attacker with network access can exploit this vulnerability to download project files without the need for authentication. This poses a significant risk as it compromises the confidentiality of the system, enabling unauthorized access to potentially sensitive information. The exploit requires no user interaction, making it particularly concerning for affected systems.

Affected Version(s)

OZW672 All versions < V10.00

OZW772 All versions < V10.00

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.