Cleartext Credentials Exposure in Control Center Server and SiNVR/SiVMS Video Server
CVE-2019-19291
5.3MEDIUM
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 10 March 2020
What is CVE-2019-19291?
A significant vulnerability has been identified in the Control Center Server and SiNVR/SiVMS Video Server due to the storage of login credentials in cleartext within log files associated with the FTP service. If the FTP service is enabled, authenticated remote attackers can exploit this vulnerability to extract sensitive login credentials of other users, potentially leading to unauthorized access and data breaches. This issue underscores the importance of securing log files and considering proper configurations to mitigate risks associated with cleartext password storage.
Affected Version(s)
Control Center Server (CCS) All versions < V1.5.0
SiNVR/SiVMS Video Server All versions < V5.0.0