CVE-2019-19299

A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server applies weak cryptography when exposing device (camera) passwords. This could allow an unauthenticated remote attacker to read and decrypt the passwords and conduct further attacks.
References
Link Resource
https://cert-portal.siemens.com/productcert/pdf/ssa-844761.pdf Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:siemens:sinvr\/sivms_video_server:*:*:*:*:*:*:*:*

History

29 Apr 2022, 13:29

Type Values Removed Values Added
CWE CWE-327 CWE-326
CPE cpe:2.3:a:siemens:sinvr_3_video_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinvr_3_central_control_server:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinvr\/sivms_video_server:*:*:*:*:*:*:*:*

10 Aug 2021, 11:15

Type Values Removed Values Added
Summary A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server applies weak cryptography when exposing device (camera) passwords. This could allow an unauthenticated remote attacker to read and decrypt the passwords and conduct further attacks. A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server applies weak cryptography when exposing device (camera) passwords. This could allow an unauthenticated remote attacker to read and decrypt the passwords and conduct further attacks.

Information

Published : 2020-03-10 20:15

Updated : 2024-02-04 20:39


NVD link : CVE-2019-19299

Mitre link : CVE-2019-19299

CVE.ORG link : CVE-2019-19299


JSON object : View

Products Affected

siemens

  • sinvr\/sivms_video_server
CWE
CWE-326

Inadequate Encryption Strength