← Back to browse · API

CVE-2019-18339

Severity
CRITICAL
CVSS
9.8
EPSS
0.02652
Risk score
40.13
CISA KEV
No
PoC
No
Published
2019-12-12
Modified
2024-08-05
First seen
2026-08-07
Aliases
EUVD-2019-8128, GHSA-372Q-JMW9-5MW6
Products
Siemens:SiNVR/SiVMS Video Server All versions < V5.0.0
Sources
euvd EUVD-2019-8128

Description

A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port 5401/tcp) of the SiVMS/SiNVR Video Server contains an authentication bypass vulnerability, even when properly configured with enforced authentication. A remote attacker with network access to the Video Server could exploit this vulnerability to read the SiVMS/SiNVR users database, including the passwords of all users in obfuscated cleartext.

References