First published: Tue Sep 14 2021(Updated: )
A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires administrative user identity could allow an attacker to obtain encoded system configuration backup files. This is only possible through network access to the affected system, and successful exploitation requires no system privileges.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SINEMA Server | <14.0 | |
Siemens SINEMA Server | =14.0 | |
Siemens SINEMA Server | =14.0-sp1 | |
Siemens SINEMA Server | =14.0-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability identifier for this vulnerability is CVE-2019-10941.
CVE-2019-10941 has a severity rating of 5.3 (Medium).
The affected software for CVE-2019-10941 is Siemens SINEMA Server (All versions < V14 SP3).
The CWE classification for this vulnerability is CWE-306.
An attacker can exploit this vulnerability by obtaining encoded system configuration backup files through network access to the affected SINEMA Server.