« Volver al listado

CVE-2023-30898

Estado: ModificadaAlta (8.8)—

A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All versions < V21.2 HotfixRev8), Siveillance Video 2022 R1 (All versions < V22.1 HotfixRev7), Siveillance Video 2022 R2 (All versions < V22.2 HotfixRev5), Siveillance Video 2022 R3 (All versions < V22.3 HotfixRev2), Siveillance Video 2023 R1 (All versions < V23.1 HotfixRev1). The Event Server component of affected applications deserializes data without sufficient validations. This could allow an authenticated remote attacker to execute code on the affected system.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-30898",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-30898",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-28T18:34:21.621367Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "productcert@siemens.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.9,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "productcert@siemens.com",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "Siveillance Video 2020 R2",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V20.2 HotfixRev14"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "Siveillance Video 2020 R3",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V20.3 HotfixRev12"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "Siveillance Video 2021 R1",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V21.1 HotfixRev12"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "Siveillance Video 2021 R2",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V21.2 HotfixRev8"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "Siveillance Video 2022 R1",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V22.1 HotfixRev7"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "Siveillance Video 2022 R2",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V22.2 HotfixRev5"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "Siveillance Video 2022 R3",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V22.3 HotfixRev2"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "Siveillance Video 2023 R1",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V23.1 HotfixRev1"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-05-09T13:15:18.107",
  "references": [
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-789345.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "productcert@siemens.com"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-789345.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "productcert@siemens.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All versions < V21.2 HotfixRev8), Siveillance Video 2022 R1 (All versions < V22.1 HotfixRev7), Siveillance Video 2022 R2 (All versions < V22.2 HotfixRev5), Siveillance Video 2022 R3 (All versions < V22.3 HotfixRev2), Siveillance Video 2023 R1 (All versions < V23.1 HotfixRev1). The Event Server component of affected applications deserializes data without sufficient validations. This could allow an authenticated remote attacker to execute code on the affected system."
    }
  ],
  "lastModified": "2026-06-17T05:55:51.027",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:siveillance_video:2020:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A37DE78-2274-4A7E-9C88-6BCC3385EB8C"
            },
            {
              "criteria": "cpe:2.3:a:siemens:siveillance_video:2020:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FFC3116-F2BD-4AFF-9700-F9CA306D37D9"
            },
            {
              "criteria": "cpe:2.3:a:siemens:siveillance_video:2021:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AF92046-F73F-4128-9EDB-993856B9880F"
            },
            {
              "criteria": "cpe:2.3:a:siemens:siveillance_video:2021:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE398796-4965-446D-A318-2E37DF0D653B"
            },
            {
              "criteria": "cpe:2.3:a:siemens:siveillance_video:2022:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F4A6472-67AE-41E0-9778-F698F8489F48"
            },
            {
              "criteria": "cpe:2.3:a:siemens:siveillance_video:2022:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B5D26B1-8D4B-418F-88F6-95AB26F4CEF0"
            },
            {
              "criteria": "cpe:2.3:a:siemens:siveillance_video:2022:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04958C83-36AF-4365-B94B-56D307F14A41"
            },
            {
              "criteria": "cpe:2.3:a:siemens:siveillance_video:2023:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C1C3E3C-16FE-4215-AFC6-DECCDEA858EB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "productcert@siemens.com"
}