High severity7.5NVD Advisory· Published Mar 10, 2020· Updated Jun 17, 2026
CVE-2019-19299
CVE-2019-19299
Description
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0 < V5.0.2), SiNVR/SiVMS Video Server (All versions >= V5.0.2). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server applies weak cryptography when exposing device (camera) passwords. This could allow an unauthenticated remote attacker to read and decrypt the passwords and conduct further attacks.
Affected products
4cpe:2.3:a:siemens:sinvr\/sivms_video_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:siemens:sinvr\/sivms_video_server:*:*:*:*:*:*:*:*range: <=5.0.2
- (no CPE)
- Range: All versions >= V5.0.2
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-844761.pdfnvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.