PT-2020-2349 · Siemens · Sinvr/Sivms Video Server

Published

2020-03-10

·

Updated

2024-01-09

·

CVE-2019-19299

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions SiNVR/SiVMS Video Server versions prior to V5.0.0 SiNVR/SiVMS Video Server versions V5.0.0 through V5.0.1
Description A vulnerability has been identified in the streaming service of the SiVMS/SiNVR Video Server, which applies weak cryptography when exposing device passwords. This could allow an unauthenticated remote attacker to read and decrypt the passwords and conduct further attacks. The issue is related to the default port 5410/tcp.
Recommendations For versions prior to V5.0.0, update to version V5.0.0 or later. For versions V5.0.0 through V5.0.1, update to version V5.0.2 or later. As a temporary workaround, consider restricting access to the streaming service on port 5410/tcp to minimize the risk of exploitation.

Fix

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

BDU:2020-02317
CVE-2019-19299

Affected Products

Sinvr/Sivms Video Server