Security Logging Oversight in Control Center Server by Siemens
CVE-2019-19295
4.3MEDIUM
Summary
A vulnerability exists in Siemens Control Center Server (CCS) prior to version 1.5.0 due to the lack of enforcement for logging security-relevant activities in its XML-based communication protocol. This gap allows an authenticated remote attacker to exploit the system and execute covert actions that remain undetected in the application log, posing significant risks to security and operational integrity. The affected services communicate over TCP ports 5444 and 5440 by default.
Affected Version(s)
Control Center Server (CCS) All versions < V1.5.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved