A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1)
Published Jan 16, 2020
9.9
CRITICALCVSS 3.1
EPSS 1.21%
Description
A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1). Incorrect session validation could allow an attacker with a valid session, with low privileges, to perform firmware updates and other administrative operations on connected devices. The security vulnerability could be exploited by an attacker with network access to the affected system. An attacker must have access to a low privileged account in order to exploit the vulnerability. An attacker could use the vulnerability to compromise confidentiality, integrity, and availability of the affected system and underlying components. At the time of advisory publication no public exploitation of this security vulnerability was known.
Affected products
-
Affected
- All versions < V14.0 SP2 Update 1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Siemens AG | SINEMA Server | unknown | Affected
|
- < 14.0
- 14.0
- 14.0
- 14.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://cert-portal.siemens.com/productcert/pdf/ssa-880233.pdf x_refsource_CONFIRMVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2654 Advisory
- https://www.us-cert.gov/ics/advisories/icsa-20-014-02 x_refsource_MISCThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-880233.pdf | x_refsource_CONFIRMVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2654 | Advisory | |
| https://www.us-cert.gov/ics/advisories/icsa-20-014-02 | x_refsource_MISCThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data