cbcvebase.
CVE-2019-13918
published 2019-09-13

CVE-2019-13918: A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing…

PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.51%
71.7th percentile
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to the vulnerable software, requiring no privileges and no user interaction. The vulnerability could allow full access to the web interface. At the time of advisory publication no public exploitation of this security vulnerability was known.

Affected

3 ranges
VendorProductVersion rangeFixed in
siemenssinema_remote_connect_server< 2.02.0
siemenssinema_remote_connect_server
siemens_agsinema_remote_connect_server

Detection & IOCsextracted from sources · hover to see the quote

  • No authentication attempt rate-limiting or lockout exists on the SINEMA Remote Connect Server web interface, enabling brute-force/password-guessing attacks remotely with no privileges required.
  • Monitor for high volumes of repeated authentication attempts against the SINEMA Remote Connect Server web interface from a single source, indicative of automated password guessing.
  • Restrict and monitor network access to the SINEMA Remote Connect web interface; unexpected external access attempts should be treated as suspicious.
  • ·All versions of SINEMA Remote Connect Server prior to V2.0 SP1 are vulnerable; the fix is available in V2.0 SP1 or later.
  • ·No public exploits were known at the time of advisory publication, but a high skill level is noted as needed to exploit.
  • ·The CVSS v3 base score is 8.1 with attack vector Network, no privileges required, and no user interaction, reflecting the severity of unauthenticated remote brute-force exposure.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.