Security Logging Oversight in Control Center Server by Siemens
CVE-2019-19295

4.3MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
10 March 2020

Summary

A vulnerability exists in Siemens Control Center Server (CCS) prior to version 1.5.0 due to the lack of enforcement for logging security-relevant activities in its XML-based communication protocol. This gap allows an authenticated remote attacker to exploit the system and execute covert actions that remain undetected in the application log, posing significant risks to security and operational integrity. The affected services communicate over TCP ports 5444 and 5440 by default.

Affected Version(s)

Control Center Server (CCS) All versions < V1.5.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.