CVE-2019-19290 is a path traversal vulnerability in the DOWNLOADS section of the Control Center Server (CCS) web interface, affecting all versions prior to V1.5.0 of Siemens SINVR 3 Central Control Server and SINVR 3 Video Server. This medium-severity vulnerability (CVSS 6.5) allows an authenticated remote attacker to access and download arbitrary files from the server with low attack complexity and no user interaction required, potentially leading to high confidentiality impact. While not listed in CISA's KEV catalog, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it has received limited community discussion and media coverage, primarily from Siemens product security advisories.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:siemens:sinvr_3_central_control_server:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:siemens:sinvr_3_video_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.