First published: Tue May 09 2023(Updated: )
A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All versions < V21.2 HotfixRev8), Siveillance Video 2022 R1 (All versions < V22.1 HotfixRev7), Siveillance Video 2022 R2 (All versions < V22.2 HotfixRev5), Siveillance Video 2022 R3 (All versions < V22.3 HotfixRev2), Siveillance Video 2023 R1 (All versions < V23.1 HotfixRev1). The Event Server component of affected applications deserializes data without sufficient validations. This could allow an authenticated remote attacker to execute code on the affected system.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Siveillance Vms Video | =2020-r2 | |
Siemens Siveillance Vms Video | =2020-r3 | |
Siemens Siveillance Vms Video | =2021-r1 | |
Siemens Siveillance Vms Video | =2021-r2 | |
Siemens Siveillance Vms Video | =2022-r1 | |
Siemens Siveillance Vms Video | =2022-r2 | |
Siemens Siveillance Vms Video | =2022-r3 | |
Siemens Siveillance Vms Video | =2023-r1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30898 has been classified as a high severity vulnerability.
To remediate CVE-2023-30898, upgrade to the latest version of Siveillance Video as specified in the vendor advisory.
CVE-2023-30898 affects Siveillance Video versions prior to v20.2 HotfixRev14, v20.3 HotfixRev12, v21.1 HotfixRev12, v21.2 HotfixRev8, and others.
CVE-2023-30898 impacts Siemens Siveillance Video systems across multiple versions.
Yes, Siemens has released patches for CVE-2023-30898 in the updated versions of Siveillance Video.