First published: Tue Mar 10 2020(Updated: )
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The web interface of the Control Center Server (CCS) contains a reflected Cross-site Scripting (XSS) vulnerability that could allow an unauthenticated remote attacker to steal sensitive data or execute administrative actions on behalf of a legitimate administrator of the CCS web interface.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Sinvr 3 Central Control Server | ||
Siemens Sinvr 3 Video Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19293 has been classified as a medium severity vulnerability due to its potential impact on sensitive data.
To fix CVE-2019-19293, upgrade the Control Center Server (CCS) to version 1.5.0 or higher which addresses the reflected XSS vulnerability.
Yes, CVE-2019-19293 affects all versions of Control Center Server prior to version 1.5.0.
Yes, CVE-2019-19293 could allow an unauthenticated remote attacker to exploit the vulnerability.
CVE-2019-19293 impacts Siemens Sinvr 3 Central Control Server and Siemens Sinvr 3 Video Server.