#VU23599 Missing Authentication for Critical Function in SiNVR 3 Video Server - CVE-2019-18339
Published: December 13, 2019
SiNVR 3 Video Server
Siemens
Description
The vulnerability allows a remote attacker to gain access to sensitive information on the target system.
The vulnerability exists due to the HTTP service (default port 5401/tcp) contains an authentication bypass vulnerability. A remote attacker can read the SiNVR users database, including the passwords of all users in obfuscated cleartext.