ICSA-19-344-02
·
Published 2021-04-13
·
View on CISA ICS-CERT ↗
Siemens and PKE SiNVR, SiVMS Video Server (Update A)
CVSS 9.8
CRITICAL
Risk Summary
Successful exploitation of these vulnerabilities could allow an attacker to read the SiVMS/SiNVR users database, including the passwords of all users in obfuscated cleartext and configuration files.
CVEs (2)
Remediations
- Siemens recommends users to update to v5.0.0 or later.
- Siemens has identified the following specific workarounds and mitigations that users can apply to reduce the risk:
- As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens ' operational guidelines for industrial security and to following the recommendations in the product manuals.
- Additional information on industrial security by Siemens can be found at:https://www.siemens.com/industrialsecurity
- For more information on these vulnerabilities and more detailed mitigation instructions, please see Siemens security advisory SSA-761617 and the PKE security advisory.
Affected Vendors
Siemens
Affected Products (3)
Siemens
·
SiNVR/SiVMS Video Server
>= 5.0.0 | CVE-2019-18340
Siemens
·
SiNVR 3 Central Control Server (CCS)
- SSA-761844 and ICSA-21-103-10
Siemens
·
SiNVR/SiVMS Video Server
< 5.0.0
Affected Sectors
Commercial Facilities
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more