Back to overview

CVE-2019-18342

CRITICAL
9.9
CVSS 3.1
Description
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Center Server (CCS) does not properly limit its capabilities to the specified purpose. In conjunction with CVE-2019-18341, an unauthenticated remote attacker with network access to the CCS server could exploit this vulnerability to read or delete arbitrary files, or access other resources on the same server.

Metadata

CVE ID
CVE-2019-18342
State
PUBLISHED
Assigner
siemens
Reserved
2019-10-23 00:00 UTC
Published
2019-12-12 19:08 UTC
Last updated
2024-08-05 01:54 UTC
Primary CWE
CWE-749
CWE-749: Exposed Dangerous Method or Function
Vendor / Product
Siemens / Control Center Server (CCS)
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:F/RL:U/RC:C
Affected products (1)
VendorProductPlatformVersions
Siemens Control Center Server (CCS) All versions < V1.5.0
Weakness (CWE)
CWESourceDescription
CWE-749 cna CWE-749: Exposed Dangerous Method or Function
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:F/RL:U/RC:C
Back to overview