CVE-2019-18315: Critical severity siemens sppa-t3000 application server vulnerability
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets to 8888/tcp. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2019-18315.
What is the severity of CVE-2019-18315?
The severity of CVE-2019-18315 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2019-18315?
CVE-2019-18315 affects SPPA-T3000 Application Server versions up to and including Service Pack R8.2 SP1.
How can an attacker exploit CVE-2019-18315?
An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets to 8888/tcp.
Is there a fix available for CVE-2019-18315?
Yes, to mitigate the vulnerability, it is recommended to update to Service Pack R8.2 SP2 or a later version.