CVE-2019-10941 PUBLISHED CVSS 5.300000190734863 MEDIUM

A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires administrative user identity could allow an attacker to obtain encoded system configuration backup files. This is only possible through network access to the affected system, and successful exploitation requires no system privileges.

EPSS 0.18% · 40.0th percentile

Risk Scores

CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.18%
40.0th percentile

Affected Products

VendorProductVersions
SiemensSINEMA ServerAll versions < V14 SP3
siemenssinema_server0, 14.0, 14.0

Timeline

References

…and 2 more

Open in Interactive Console →