Weak Cryptography in Control Center Server and SiVMS Video Server by Siemens
CVE-2019-18340

5.5MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
12 December 2019

Summary

A vulnerability exists in Siemens Control Center Server and SiVMS/SiNVR Video Server due to the use of weak cryptographic techniques for storing user and device passwords. This allows a local attacker to potentially exploit the vulnerability by extracting sensitive passwords from the user database and device configuration files, leading to possible unauthorized access and further attacks.

Affected Version(s)

Control Center Server (CCS) All versions < V1.5.0

Control Center Server (CCS) All versions >= V1.5.0

SiNVR/SiVMS Video Server All versions < V5.0.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.