siemens sinema-server CVE-2019-10940 is a vulnerability in Siemens Sinema Server
Published on January 16, 2020

A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1). Incorrect session validation could allow an attacker with a valid session, with low privileges, to perform firmware updates and other administrative operations on connected devices. The security vulnerability could be exploited by an attacker with network access to the affected system. An attacker must have access to a low privileged account in order to exploit the vulnerability. An attacker could use the vulnerability to compromise confidentiality, integrity, and availability of the affected system and underlying components. At the time of advisory publication no public exploitation of this security vulnerability was known.

NVD

Weakness Type

Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.


Products Associated with CVE-2019-10940

Want to know whenever a new CVE is published for Siemens Sinema Server? stack.watch will email you.

 

Affected Versions

Siemens AG SINEMA Server Version All versions < V14.0 SP2 Update 1 is affected by CVE-2019-10940

Exploit Probability

EPSS
0.18%
Percentile
39.48%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.