CVE-2019-18340 is a vulnerability affecting Siemens Control Center Server (CCS) and SiNVR/SiVMS Video Server products across all versions. It stems from the use of weak cryptography to store user and device passwords, allowing a local attacker to extract these credentials. Rated Medium severity (CVSS 5.5), this vulnerability requires local access and low privileges, but grants high confidentiality impact by exposing sensitive passwords. There is no evidence of active exploitation, public exploit code, or KEV listing, though it has garnered moderate community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:siemens:sinvr_3_central_control_server:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:siemens:sinvr_3_video_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.