CVE-2019-18286: Infoleak
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes directory listings and files containing sensitive information. This vulnerability is independent from CVE-2019-18287. Please note that an attacker needs to have access to the Application Highway in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18286?
CVE-2019-18286 is a vulnerability in the SPPA-T3000 Application Server that exposes directory listings and files containing sensitive information.
What versions of SPPA-T3000 Application Server are affected by CVE-2019-18286?
All versions of SPPA-T3000 Application Server prior to Service Pack R8.2 SP2 are affected.
What is the severity of CVE-2019-18286?
The severity of CVE-2019-18286 is medium (5.3).
How can an attacker exploit CVE-2019-18286?
An attacker needs to have access to the server to exploit CVE-2019-18286 and can obtain sensitive information through the exposed directory listings and files.
Are there any security advisories or references related to CVE-2019-18286?
Yes, you can find more information in the following security advisories and references: - [Packet Storm Security Advisory](http://packetstormsecurity.com/files/155665/Siemens-Security-Advisory-SPPA-T3000-Code-Execution.html) - [Siemens ProductCERT Advisory](https://cert-portal.siemens.com/productcert/pdf/ssa-451445.pdf)