Vulnerability Details CVE-2019-19296
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The two FTP services (default ports 21/tcp and 5411/tcp) of the SiVMS/SiNVR Video
Server contain a path traversal vulnerability
that could allow an authenticated remote attacker to access and download
arbitrary files from the server, if the FTP services are enabled.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.6%
CVSS Severity
CVSS v3 Score 6.8
CVSS v2 Score 4.9
Products affected by CVE-2019-19296
-
cpe:2.3:a:siemens:sinvr_3_central_control_server:-
-
cpe:2.3:a:siemens:sinvr_3_video_server:-