CVE-2019-13947 PUBLISHED CVSS 4.900000095367432 MEDIUM

A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The user configuration menu in the web interface of the Control Center Server (CCS) transfers user passwords in clear to the client (browser). An attacker with administrative privileges for the web interface could be able to read (and not only reset) passwords of other CCS users.

EPSS 0.17% · 38.3th percentile

Risk Scores

CVSS v3.1
4.900000095367432
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C
EPSS Score
0.17%
38.3th percentile

Affected Products

VendorProductVersions
siemenssinvr_3_central_control_server
SiemensControl Center Server (CCS)All versions < V1.5.0
siemenssinvr_3_video_server

Timeline

References

Open in Interactive Console →