CVE-2019-10941
published 2021-09-14CVE-2019-10941: A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires administrative user…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.83%
53.3th percentile
A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires administrative user identity could allow an attacker to obtain encoded system configuration backup files. This is only possible through network access to the affected system, and successful exploitation requires no system privileges.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | sinema_server | < 14.0 | 14.0 |
| siemens | sinema_server | — | — |
| siemens | sinema_server | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEMA Server
cisa_ics·2021-09-14·CVSS 5.3
[MEDIUM] Siemens SINEMA Server
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEMA Server
Last RevisedSeptember 14, 2021
Alert CodeICSA-21-257-12
## 1. EXECUTIVE SUMMARY
- CVSS v3 4.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEMA Server
- Vulnerability: Missing Authentication for Critical Function
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to obtain encoded system configuration backup files.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of SINEMA Server, a network monitoring and management software, are affected:
-
GHSA
GHSA-69h3-7gjf-m5gx: A vulnerability has been identified in SINEMA Server (All versions < V14 SP3)
ghsa_unreviewed·2022-05-24
CVE-2019-10941 [MEDIUM] CWE-306 GHSA-69h3-7gjf-m5gx: A vulnerability has been identified in SINEMA Server (All versions < V14 SP3)
A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires administrative user identity could allow an attacker to obtain encoded system configuration backup files. This is only possible through network access to the affected system, and successful exploitation requires no system privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-09-14
Published