{"containers":{"cna":{"providerMetadata":{"orgId":"cec7a2ec-15b4-4faf-bd53-b40f371f3a77","shortName":"siemens","dateUpdated":"2024-01-09T09:56:14.606Z"},"descriptions":[{"lang":"en","value":"A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), Control Center Server (CCS) (All versions >= V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0). Both the SiVMS/SiNVR Video Server and the Control Center Server (CCS) store\nuser and device passwords by applying weak cryptography.\n\nA local attacker could exploit this vulnerability to extract\nthe passwords from the user database and/or the device configuration files\nto conduct further attacks."}],"affected":[{"vendor":"Siemens","product":"Control Center Server (CCS)","versions":[{"version":"All versions < V1.5.0","status":"affected"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"Control Center Server (CCS)","versions":[{"version":"All versions >= V1.5.0","status":"affected"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SiNVR/SiVMS Video Server","versions":[{"version":"All versions < V5.0.0","status":"affected"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SiNVR/SiVMS Video Server","versions":[{"version":"All versions >= V5.0.0","status":"affected"}],"defaultStatus":"unknown"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C","baseScore":5.5,"baseSeverity":"MEDIUM"}}],"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-327","description":"CWE-327: Use of a Broken or Risky Cryptographic Algorithm","type":"CWE"}]}],"references":[{"tags":["x_refsource_MISC"],"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-761617.pdf"},{"tags":["x_refsource_CONFIRM"],"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-761844.pdf"}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-05T01:54:14.118Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-761617.pdf"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-761844.pdf"}]}]},"cveMetadata":{"assignerOrgId":"cec7a2ec-15b4-4faf-bd53-b40f371f3a77","assignerShortName":"siemens","cveId":"CVE-2019-18340","datePublished":"2019-12-12T19:08:49.000Z","dateReserved":"2019-10-23T00:00:00.000Z","dateUpdated":"2024-08-05T01:54:14.118Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}