CVE-2019-19299
EUVD-2019-892310.03.2020, 20:15
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0 < V5.0.2), SiNVR/SiVMS Video Server (All versions >= V5.0.2). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server applies weak cryptography when exposing device (camera) passwords. This could allow an unauthenticated remote attacker to read and decrypt the passwords and conduct further attacks.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| siemens | sinvr\/sivms_video_server | 𝑥 ≤ 5.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration