#VU23595 Cleartext transmission of sensitive information in SiNVR 3 Central Control Server (CCS) - CVE-2019-13947
Published: December 13, 2019
SiNVR 3 Central Control Server (CCS)
Siemens
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the user configuration menu in the web interface transfers user passwords in cleartext to the client (browser). A remote authenticated administrator with ability to intercept network traffic can gain access to sensitive data.