SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-19294

A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0).

MEDIUM 6.3EPSS 1.01%

Does this matter?

Lower severity and a low EPSS score (1.01%). Track it; it rarely justifies an emergency change on its own.

Description

A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The web interface of the Control Center Server (CCS) contains multiple stored Cross-site Scripting (XSS) vulnerabilities in several input fields. This could allow an authenticated remote attacker to inject malicious JavaScript code into the CCS web application that is later executed in the browser context of any other user who views the relevant CCS web content.

CVSS 3.1
6.3 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
EPSS
1.01% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
siemens/sinvr 3 central control server · siemens/sinvr 3 video server
Source
productcert@siemens.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.