SFTP Service Vulnerability in Control Center Server by Siemens
CVE-2019-18342
9.9CRITICAL
Summary
A security vulnerability exists in the SFTP service of the Control Center Server (CCS) versions prior to V1.5.0, allowing unauthenticated remote attackers with network access to gain unauthorized access. This could enable them to read or delete arbitrary files, or potentially access other resources on the same server. The inadequate restrictions on the SFTP service could be exploited alongside associated vulnerabilities, increasing the risk of significant data breaches and unauthorized actions.
Affected Version(s)
Control Center Server (CCS) All versions < V1.5.0
References
CVSS V3.1
Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved