CVE-2019-6581
A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VMS 2018 R3 (All versions < V12.3a), Siveillance VMS 2019 R1 (All versions < V13.1a). An attacker with network access to port 80/TCP could change user roles without proper authorization. The security vulnerability could be exploited by an authenticated attacker with network access to the affected service. No user interaction is required to exploit this security vulnerability.
Leer descripción completaMostrar menos
Successful exploitation compromises confidentiality, integrity and availability of the targeted system. At the time of advisory publication no public exploitation of this security vulnerability was known.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.27%
- Percentil entre todas las CVEs puntuadas: 69
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (5)
CWE
- CWE-285
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-6581",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "productcert@siemens.com",
"affectedData": [
{
"vendor": "Siemens AG",
"product": "Siveillance VMS 2017 R2",
"versions": [
{
"status": "affected",
"version": "All versions < V11.2a"
}
]
},
{
"vendor": "Siemens AG",
"product": "Siveillance VMS 2018 R1",
"versions": [
{
"status": "affected",
"version": "All versions < V12.1a"
}
]
},
{
"vendor": "Siemens AG",
"product": "Siveillance VMS 2018 R2",
"versions": [
{
"status": "affected",
"version": "All versions < V12.2a"
}
]
},
{
"vendor": "Siemens AG",
"product": "Siveillance VMS 2018 R3",
"versions": [
{
"status": "affected",
"version": "All versions < V12.3a"
}
]
},
{
"vendor": "Siemens AG",
"product": "Siveillance VMS 2019 R1",
"versions": [
{
"status": "affected",
"version": "All versions < V13.1a"
}
]
}
]
}
],
"published": "2019-06-12T14:29:06.057",
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-212009.pdf",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "productcert@siemens.com"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-19-162-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "productcert@siemens.com"
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-212009.pdf",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-19-162-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "productcert@siemens.com",
"description": [
{
"lang": "en",
"value": "CWE-285"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VMS 2018 R3 (All versions < V12.3a), Siveillance VMS 2019 R1 (All versions < V13.1a). An attacker with network access to port 80/TCP could change user roles without proper authorization. The security vulnerability could be exploited by an authenticated attacker with network access to the affected service. No user interaction is required to exploit this security vulnerability. Successful exploitation compromises confidentiality, integrity and availability of the targeted system. At the time of advisory publication no public exploitation of this security vulnerability was known."
},
{
"lang": "es",
"value": "Se ha identificado una vulnerabilidad en Siveillance VMS 2017 R2 (todas las versiones anteriores a la V11.2a), Siveillance VMS 2018 R1 (todas las versiones anteriores a la V12.1a), Siveillance VMS 2018 R2 (todas las versiones anteriores a la V12.2a), Siveillance VMS 2018 R3 (todas las versiones anteriores a la V12.3a), Siveillance VMS 2019 R1 (todas las versiones anteriores a la V13.1a). Un atacante con acceso de red al puerto 80 / TCP podría cambiar los roles de los usuarios sin la debida autorización. La vulnerabilidad de la seguridad podría ser explotada por un atacante autenticado con acceso de red al servicio afectado. No se requiere la interacción del usuario para explotar esta vulnerabilidad de seguridad. La explotación con éxito compromete la confidencialidad, integridad y disponibilidad del sistema objetivo. En el momento de la publicación de asesoramiento, no se conocía la explotación pública de esta vulnerabilidad de seguridad."
}
],
"lastModified": "2026-06-17T02:39:18.573",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:siemens:siveillance_video_management_software_2017_r2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57B38507-984D-40E9-A3A5-40B7BF29BDF7",
"versionEndExcluding": "11.2a"
},
{
"criteria": "cpe:2.3:a:siemens:siveillance_video_management_software_2018_r1:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "323A9152-90F1-4222-8468-1C1843B30C21",
"versionEndExcluding": "12.1a"
},
{
"criteria": "cpe:2.3:a:siemens:siveillance_video_management_software_2018_r2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EA4F90DF-54F4-4757-BFBB-D3594B866B45",
"versionEndExcluding": "12.2a"
},
{
"criteria": "cpe:2.3:a:siemens:siveillance_video_management_software_2018_r3:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDA10332-9542-4C47-9870-BADDC276C160",
"versionEndExcluding": "12.3a"
},
{
"criteria": "cpe:2.3:a:siemens:siveillance_video_management_software_2019_r1:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A8464AB-5EC6-4147-90B2-19ED8FB3A4E4",
"versionEndExcluding": "13.1a"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "productcert@siemens.com"
}