Full Report
The Video Server application in SiNVR/SiVMS solutions contains two vulnerabilities involving authentication bypass (CVE-2019-18339) and information disclosure (CVE-2019-18340). PKE has released an update of the application that fixes CVE-2019-18339. This update is not available under the former Siemens OEM brand name SiNVR. For details see PKE Security Advisory at https://sivms.cloud/wp-content/uploads/2021/03/sivms-cve-fixes_1.0_EN.pdf Siemens recommends specific countermeasures to mitigate the vulnerabilities.
Analysis Summary
# Vulnerability: Authentication Bypass and Information Disclosure in SiNVR/SiVMS Video Server
## CVE Details
- **CVE ID:** CVE-2019-18339 / CVE-2019-18340
- **CVSS Score:**
- CVE-2019-18339: 9.8 (Critical)
- CVE-2019-18340: 5.3 (Medium)
- **CWE:**
- CVE-2019-18339: CWE-287 (Improper Authentication)
- CVE-2019-18340: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor)
## Affected Systems
- **Products:** SiNVR (Siemens OEM) and SiVMS (PKE) Video Server applications.
- **Versions:** All versions prior to the fixed release (SiVMS version 5.0.0 or specific application updates).
- **Configurations:** Systems where the Video Server application is accessible over the network.
## Vulnerability Description
- **CVE-2019-18339:** A flaw in the authentication mechanism of the Video Server application allows a remote attacker to bypass authentication entirely. By sending specially crafted requests, an attacker can gain unauthorized access to the system with administrative privileges.
- **CVE-2019-18340:** An information disclosure vulnerability exists where the application leaks sensitive system or configuration data to unauthenticated users. This data can be used to further facilitate attacks against the infrastructure.
## Exploitation
- **Status:** PoC availability (Consult PKE advisory for specific technical validation).
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High (Full access to video feeds and system configuration).
- **Integrity:** High (Ability to modify system settings or recordings).
- **Availability:** High (Potential to disrupt video surveillance services).
## Remediation
### Patches
- **SiVMS (PKE):** PKE has released an update for the Video Server application that addresses CVE-2019-18339. Users should upgrade to the latest available version provided by PKE.
- **SiNVR (Siemens):** Note that updates are **not** available for the legacy Siemens OEM branded "SiNVR." Users are advised to migrate to supported SiVMS versions or apply strict workarounds.
### Workarounds
- **Network Segmentation:** Isolate the Video Server within a dedicated VLAN and restrict access to trusted IP addresses only.
- **Firewall Restrictions:** Block external access to the ports used by the Video Server application (typically TCP/80, 443, or custom application ports).
- **VPN Access:** Require a secure VPN for any remote administrative access to the video management system.
## Detection
- **Indicators of Compromise:** Unusual administrative logins originating from unexpected IP addresses; unauthorized configuration changes; unexplained spikes in outbound data from the Video Server.
- **Detection methods and tools:** Review application-level logs for authentication bypass attempts and monitor network traffic for unauthorized access to the Video Server API/web interface.
## References
- **Vendor Advisory:** hxxps[://]sivms[.]cloud/wp-content/uploads/2021/03/sivms-cve-fixes_1.0_EN[.]pdf
- **Siemens Security Advisory:** hxxps[://]cert-portal[.]siemens[.]com/productcert/pdf/ssa-761617[.]pdf