CVE-2019-10941
Published on: 09/14/2021 12:00:00 AM UTC
Last Modified on: 09/23/2021 03:39:00 PM UTC
Certain versions of Sinema Server from Siemens contain the following vulnerability:
A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires administrative user identity could allow an attacker to obtain encoded system configuration backup files. This is only possible through network access to the affected system, and successful exploitation requires no system privileges.
- CVE-2019-10941 has been assigned by
productc[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Siemens - SINEMA Server version All versions < V14 SP3
CVSS3 Score: 5.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | NONE | NONE |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
cert-portal.siemens.com application/pdf |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Siemens | Sinema Server | All | All | All | All |
Application | Siemens | Sinema Server | 14.0 | - | All | All |
Application | Siemens | Sinema Server | 14.0 | sp1 | All | All |
Application | Siemens | Sinema Server | 14.0 | sp2 | All | All |
- cpe:2.3:a:siemens:sinema_server:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinema_server:14.0:-:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinema_server:14.0:sp1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinema_server:14.0:sp2:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2019-10941 : A vulnerability has been identified in SINEMA Server All versions < V14 SP3 . Missing authenticat… twitter.com/i/web/status/1… | 2021-09-14 10:55:01 |