CVE-2019-19295 describes a logging vulnerability in Siemens Control Center Server (CCS) versions prior to V1.5.0, affecting both the SINVR 3 Central Control Server and Video Server. An authenticated remote attacker can exploit this flaw via the XML-based communication protocol on ports 5444/tcp and 5440/tcp to perform actions that are not recorded in the application log. This medium-severity vulnerability (CVSS 4.3) has a low attack complexity and requires prior authentication, with a potential impact of low integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:siemens:sinvr_3_central_control_server:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:siemens:sinvr_3_video_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.