Weak Cryptography in Control Center Server and SiVMS Video Server by Siemens
CVE-2019-18340
5.5MEDIUM
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 12 December 2019
Summary
A vulnerability exists in Siemens Control Center Server and SiVMS/SiNVR Video Server due to the use of weak cryptographic techniques for storing user and device passwords. This allows a local attacker to potentially exploit the vulnerability by extracting sensitive passwords from the user database and device configuration files, leading to possible unauthorized access and further attacks.
Affected Version(s)
Control Center Server (CCS) All versions < V1.5.0
Control Center Server (CCS) All versions >= V1.5.0
SiNVR/SiVMS Video Server All versions < V5.0.0
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved