Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-13947

Опубликовано: 12 дек. 2019
Источник: nvd
CVSS3: 4.9
CVSS2: 4
EPSS Низкий

Описание

A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The user configuration menu in the web interface of the Control Center Server (CCS) transfers user passwords in clear to the client (browser).

An attacker with administrative privileges for the web interface could be able to read (and not only reset) passwords of other CCS users.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:siemens:sinvr_3_central_control_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinvr_3_video_server:*:*:*:*:*:*:*:*

EPSS

Процентиль: 40%
0.00181
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-317
CWE-312

Связанные уязвимости

CVSS3: 4.9
github
больше 3 лет назад

A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR 3 Video Server (all versions). The user configuration menu in the web interface of the SiNVR 3 Central Control Server (CCS) transfers user passwords in clear to the client (browser). An attacker with administrative privileges for the web interface could be able to read (and not only reset) passwords of other SiNVR 3 CCS users.

EPSS

Процентиль: 40%
0.00181
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-317
CWE-312