CVE-2019-19293 is a reflected Cross-site Scripting (XSS) vulnerability affecting all versions of Siemens Control Center Server (CCS) prior to V1.5.0, including SINVR 3 Central Control Server and SINVR 3 Video Server. This medium-severity vulnerability (CVSS 6.1) allows an unauthenticated remote attacker, with high attack complexity, to potentially steal sensitive data or execute administrative actions on behalf of a legitimate administrator through the web interface. There is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:siemens:sinvr_3_central_control_server:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:siemens:sinvr_3_video_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.