← Back to home
ICSA-19-344-02  ·  Published 2021-04-13  ·  View on CISA ICS-CERT ↗

Siemens and PKE SiNVR, SiVMS Video Server (Update A)

CVSS 9.8 CRITICAL

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to read the SiVMS/SiNVR users database, including the passwords of all users in obfuscated cleartext and configuration files.

Remediations

  • Siemens recommends users to update to v5.0.0 or later.
  • Siemens has identified the following specific workarounds and mitigations that users can apply to reduce the risk:
  • As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens ' operational guidelines for industrial security and to following the recommendations in the product manuals.
  • Additional information on industrial security by Siemens can be found at:https://www.siemens.com/industrialsecurity
  • For more information on these vulnerabilities and more detailed mitigation instructions, please see Siemens security advisory SSA-761617 and the PKE security advisory.

Affected Vendors

Siemens

Affected Products (3)

Siemens · SiNVR/SiVMS Video Server >= 5.0.0 | CVE-2019-18340
Siemens · SiNVR 3 Central Control Server (CCS) - SSA-761844 and ICSA-21-103-10
Siemens · SiNVR/SiVMS Video Server < 5.0.0

Affected Sectors

Commercial Facilities

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more