CVE-2019-18342 PUBLISHED CVSS 9.899999618530273 CRITICAL

A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Center Server (CCS) does not properly limit its capabilities to the specified purpose. In conjunction with CVE-2019-18341, an unauthenticated remote attacker with network access to the CCS server could exploit this vulnerability to read or delete arbitrary files, or access other resources on the same server.

EPSS 0.57% · 68.4th percentile

Risk Scores

CVSS v3.1
9.899999618530273
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:F/RL:U/RC:C
EPSS Score
0.57%
68.4th percentile

Affected Products

VendorProductVersions
SiemensControl Center Server (CCS)All versions < V1.5.0
siemenscontrol_center_server0

Timeline

References

Open in Interactive Console →