- Description
- A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All versions < V21.2 HotfixRev8), Siveillance Video 2022 R1 (All versions < V22.1 HotfixRev7), Siveillance Video 2022 R2 (All versions < V22.2 HotfixRev5), Siveillance Video 2022 R3 (All versions < V22.3 HotfixRev2), Siveillance Video 2023 R1 (All versions < V23.1 HotfixRev1). The Management Server component of affected applications deserializes data without sufficient validations. This could allow an authenticated remote attacker to execute code on the affected system.
- Source
- productcert@siemens.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- productcert@siemens.com
- CWE-502
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:siemens:siveillance_video:2020:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A37DE78-2274-4A7E-9C88-6BCC3385EB8C"
},
{
"criteria": "cpe:2.3:a:siemens:siveillance_video:2020:r3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6FFC3116-F2BD-4AFF-9700-F9CA306D37D9"
},
{
"criteria": "cpe:2.3:a:siemens:siveillance_video:2021:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9AF92046-F73F-4128-9EDB-993856B9880F"
},
{
"criteria": "cpe:2.3:a:siemens:siveillance_video:2021:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CE398796-4965-446D-A318-2E37DF0D653B"
},
{
"criteria": "cpe:2.3:a:siemens:siveillance_video:2022:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F4A6472-67AE-41E0-9778-F698F8489F48"
},
{
"criteria": "cpe:2.3:a:siemens:siveillance_video:2022:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B5D26B1-8D4B-418F-88F6-95AB26F4CEF0"
},
{
"criteria": "cpe:2.3:a:siemens:siveillance_video:2022:r3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "04958C83-36AF-4365-B94B-56D307F14A41"
},
{
"criteria": "cpe:2.3:a:siemens:siveillance_video:2023:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5C1C3E3C-16FE-4215-AFC6-DECCDEA858EB"
}
],
"operator": "OR"
}
]
}
]