PT-2020-2443 · Siemens · Control Center Server+1

Published

2020-03-10

·

Updated

2024-01-09

·

CVE-2019-19291

CVSS v2.0

6.3

Medium

VectorAV:N/AC:M/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Control Center Server (CCS) versions prior to V1.5.0 SiNVR/SiVMS Video Server versions prior to V5.0.0
Description A vulnerability has been identified where the FTP services of the SiVMS/SiNVR Video Server and the Control Center Server (CCS) maintain log files that store login credentials in cleartext. In configurations where the FTP service is enabled, authenticated remote attackers could extract login credentials of other users of the service. This issue is related to the unencrypted storage of credentials, which could allow a remote attacker to gain unauthorized access to user credentials.
Recommendations For Control Center Server (CCS) versions prior to V1.5.0, update to version V1.5.0 or later to resolve the issue. For SiNVR/SiVMS Video Server versions prior to V5.0.0, update to version V5.0.0 or later to resolve the issue. As a temporary workaround, consider disabling the FTP service in the affected servers until a patch is available. Restrict access to the log files that store login credentials to minimize the risk of exploitation.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2020-02453
CVE-2019-19291

Affected Products

Control Center Server
Sinvr/Sivms Video Server