SFTP Service Vulnerability in Control Center Server by Siemens
CVE-2019-18342

9.9CRITICAL

Key Information:

Vendor
Siemens
Vendor
CVE Published:
12 December 2019

Summary

A security vulnerability exists in the SFTP service of the Control Center Server (CCS) versions prior to V1.5.0, allowing unauthenticated remote attackers with network access to gain unauthorized access. This could enable them to read or delete arbitrary files, or potentially access other resources on the same server. The inadequate restrictions on the SFTP service could be exploited alongside associated vulnerabilities, increasing the risk of significant data breaches and unauthorized actions.

Affected Version(s)

Control Center Server (CCS) All versions < V1.5.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.