Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-18342

Опубликовано: 12 дек. 2019
Источник: nvd
CVSS3: 9.9
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Center Server (CCS) does not properly limit its capabilities to the specified purpose.

In conjunction with CVE-2019-18341, an unauthenticated remote attacker with network access to the CCS server could exploit this vulnerability to read or delete arbitrary files, or access other resources on the same server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:siemens:control_center_server:*:*:*:*:*:*:*:*
Версия до 1.5.0 (исключая)

EPSS

Процентиль: 68%
0.00567
Низкий

9.9 Critical

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-749
NVD-CWE-Other

Связанные уязвимости

CVSS3: 9.9
github
больше 3 лет назад

A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR 3 Video Server (all versions). The SFTP service (default port 22/tcp) of the SiNVR 3 Central Control Server (CCS) does not properly limit its capabilities to the specified purpose. In conjunction with CVE-2019-18341, an unauthenticated remote attacker with network access to the CCS server could exploit this vulnerability to read or delete arbitrary files, or access other resources on the same server.

EPSS

Процентиль: 68%
0.00567
Низкий

9.9 Critical

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-749
NVD-CWE-Other