siemens sinvr-3-central-control-server CVE-2019-19299 vulnerability in Siemens Products
Published on March 10, 2020

A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0 < V5.0.2), SiNVR/SiVMS Video Server (All versions >= V5.0.2). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server applies weak cryptography when exposing device (camera) passwords. This could allow an unauthenticated remote attacker to read and decrypt the passwords and conduct further attacks.

NVD

Weakness Type

Inadequate Encryption Strength

The software stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required. A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.


Products Associated with CVE-2019-19299

Want to know whenever a new CVE is published for Siemens products? stack.watch will email you.

 
 
 

Affected Versions

Siemens SiNVR/SiVMS Video Server: Siemens SiNVR/SiVMS Video Server: Siemens SiNVR/SiVMS Video Server:

Exploit Probability

EPSS
0.46%
Percentile
63.74%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.