Rewterz
Rewterz Threat Advisory – Advantech WebAccess Multiple Vulnerabilities
September 18, 2019
Rewterz
Rewterz Threat Advisory – CVE-2019-13523 – ICS: Honeywell Performance IP Cameras and Performance NVRs Information Disclosure Vulnerability
September 18, 2019

Rewterz Threat Advisory – ICS: Siemens SINEMA Remote Connect Server Multiple Vulnerabilities

Severity

High

Analysis Summary

CVE-2019-13918

The web interface has no means to prevent password guessing attacks. This vulnerability could be exploited by an attacker with network access to the vulnerable software, requiring no privileges and no user interaction. Exploitation could allow full access to the web interface.

CVE-2019-34623

Some pages that should only be accessible by a privileged user can also be accessed by a nonprivileged user. This vulnerability could be exploited by an attacker with network access and valid credentials for the web interface. No user interaction is required. Exploitation could allow an attacker to access information they should not be able to read. The information affected by this vulnerability does not include passwords.

CVE-2019-13920

Some parts of the web application are not protected against cross-site request forgery (CSRF) attacks. This vulnerability could be exploited by an attacker who is able to trigger requests of a logged-in user to the application. Exploitation could allow switching the connectivity state of a user or a device.

CVE-2019-13922

An attacker with administrative privileges can obtain the hash of a connected device’s password. The security vulnerability could be exploited by an attacker with network access to the SINEMA Remote Connect Server and administrative privileges.

Impact

  • Privilege access
  • Cross-site request forgery (CSRF)
  • Exposure of sensitive information

Affected Vendors

Siemens

Affected Products

SINEMA Remote Connect Server versions prior to 2.0 SP1

Remediation

Siemens recommends users upgrade to Versions 2.0 SP1 or later for the affected products.

https://support.industry.siemens.com/cs/ww/en/view/109770899