CRITICAL🇵🇱 Wersja polska

CVE-2019-18342

CVSS 9.9v3.1pub. 2019-12-12upd. 2024-11-21

A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Center Server (CCS) does not properly limit its capabilities to the specified purpose. In conjunction with CVE-2019-18341, an unauthenticated remote attacker with network access to the CCS server could exploit this vulnerability to read or delete arbitrary files, or access other resources on the same server.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Siemens Control Center Server

    APP
    Siemens
    < 1.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-0300CRITICAL9.3⚠ KEVPL ✓same vendor

Buffer overflow RCE z uprawnieniami root w PAN-OS Captive Portal

CVE-2026-24858CRITICAL9.8⚠ KEVPL ✓same vendor

Fortinet – Auth Bypass przez FortiCloud SSO w wielu produktach

CVE-2025-59718CRITICAL9.8⚠ KEVPL ✓same vendor

Fortinet FortiOS/FortiProxy/FortiSwitchManager — Auth Bypass przez SAML

CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same vendor

Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+

CVE-2021-45046CRITICAL9.0⚠ KEVPL ✓same vendor

Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup