SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-18342

A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0).

CRITICAL 9.9EPSS 2.13%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Center Server (CCS) does not properly limit its capabilities to the specified purpose. In conjunction with CVE-2019-18341, an unauthenticated remote attacker with network access to the CCS server could exploit this vulnerability to read or delete arbitrary files, or access other resources on the same server.

CVSS 3.1
9.9 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS
2.13% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-749
Affected
siemens/control center server
Source
productcert@siemens.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.