VDB
SSA-761617
SSA-761617
PUBLISHED
CVSS 5.5 MEDIUM
The HTTP service (default port 5401/tcp) of the SiVMS/SiNVR Video Server contains an authentication bypass vulnerability, even when properly configured with enforced authentication. A remote attacker with network access to the Video Server could exploit this vulnerability to read the SiVMS/SiNVR users database, including the passwords of all users in obfuscated cleartext.
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SiNVR/SiVMS Video Server |
Timeline
- Dec 10, 2019 CVE Published
- Jan 9, 2024 CVE Updated