#VU23595 Cleartext transmission of sensitive information in SiNVR 3 Central Control Server (CCS) - CVE-2019-13947 

 

#VU23595 Cleartext transmission of sensitive information in SiNVR 3 Central Control Server (CCS) - CVE-2019-13947

Published: December 13, 2019


Vulnerability identifier: #VU23595
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-13947
CWE-ID: CWE-319
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
SiNVR 3 Central Control Server (CCS)
Software vendor:
Siemens

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to the user configuration menu in the web interface transfers user passwords in cleartext to the client (browser). A remote authenticated administrator with ability to intercept network traffic can gain access to sensitive data.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links