CVE-2019-18286 affects Siemens SPPA-T3000 Application Server versions prior to R8.2 SP2, allowing directory listings and sensitive file exposure. This medium-severity vulnerability (CVSS 5.3) requires an attacker to have access to the Application Highway, but once that prerequisite is met, it is easily exploitable with low attack complexity, leading to information disclosure. There is no known public exploitation, exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< r8.2CPE matchmatch criteria | cpe:2.3:a:siemens:sppa-t3000_application_server:*:*:*:*:*:*:*:* | ||
r8.2CPE matchmatch criteria | cpe:2.3:a:siemens:sppa-t3000_application_server:r8.2:-:*:*:*:*:*:* | ||
r8.2CPE matchmatch criteria | cpe:2.3:a:siemens:sppa-t3000_application_server:r8.2:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.