VDB
CVE-2019-13947
CVE-2019-13947
PUBLISHED
CVSS 4.900000095367432 MEDIUM
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The user configuration menu in the web interface of the Control Center Server (CCS) transfers user passwords in clear to the client (browser). An attacker with administrative privileges for the web interface could be able to read (and not only reset) passwords of other CCS users.
EPSS 0.17% · 38.2th percentile
Risk Scores
CVSS 3.1
4.900000095367432
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C
EPSS Score
0.17%
38.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| siemens | sinvr_3_central_control_server | |
| Siemens | Control Center Server (CCS) | All versions < V1.5.0 |
| siemens | sinvr_3_video_server |
Exploit Intelligence
Timeline
- Dec 10, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-451445.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-418979.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-170686.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-344983.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-761617.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-618620.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-525454.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-686531.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-273799.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-761844.pdf url
- https://nvd.nist.gov/vuln/detail/CVE-2019-13947 advisory