TROYANOSYVIRUS
Back to CVEs

CVE-2019-13919

MEDIUM
4.3

Description

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some pages that should only be accessible by a privileged user can also be accessed by a non-privileged user. The security vulnerability could be exploited by an attacker with network access and valid credentials for the web interface. No user interaction is required. The vulnerability could allow an attacker to access information that he should not be able to read. The affected information does not include passwords. At the time of advisory publication no public exploitation of this security vulnerability was known.

CVE Details

CVSS v3.1 Score4.3
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published9/13/2019
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

siemens:sinema_remote_connect_server

Weaknesses (CWE)

CWE-284

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.