VDB

SSA-761617

SSA-761617 PUBLISHED CVSS 5.5 MEDIUM

The HTTP service (default port 5401/tcp) of the SiVMS/SiNVR Video Server contains an authentication bypass vulnerability, even when properly configured with enforced authentication. A remote attacker with network access to the Video Server could exploit this vulnerability to read the SiVMS/SiNVR users database, including the passwords of all users in obfuscated cleartext.

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C

Affected Products

VendorProductVersions
SiemensSiNVR/SiVMS Video Server

Timeline

  • Dec 10, 2019 CVE Published
  • Jan 9, 2024 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›