{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-27T08:16:03.113","vulnerabilities":[{"cve":{"id":"CVE-2019-6581","sourceIdentifier":"productcert@siemens.com","published":"2019-06-12T14:29:06.057","lastModified":"2024-11-21T04:46:44.800","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VMS 2018 R3 (All versions < V12.3a), Siveillance VMS 2019 R1 (All versions < V13.1a). An attacker with network access to port 80/TCP could change user roles without proper authorization. The security vulnerability could be exploited by an authenticated attacker with network access to the affected service. No user interaction is required to exploit this security vulnerability. Successful exploitation compromises confidentiality, integrity and availability of the targeted system. At the time of advisory publication no public exploitation of this security vulnerability was known."},{"lang":"es","value":"Se ha identificado una vulnerabilidad en Siveillance VMS 2017 R2 (todas las versiones anteriores a la V11.2a), Siveillance VMS 2018 R1 (todas las versiones anteriores a la V12.1a), Siveillance VMS 2018 R2 (todas las versiones anteriores a la V12.2a), Siveillance VMS 2018 R3 (todas las versiones anteriores a la V12.3a), Siveillance VMS 2019 R1 (todas las versiones anteriores a la V13.1a). Un atacante con acceso de red al puerto 80 / TCP podría cambiar los roles de los usuarios sin la debida autorización. La vulnerabilidad de la seguridad podría ser explotada por un atacante autenticado con acceso de red al servicio afectado. No se requiere la interacción del usuario para explotar esta vulnerabilidad de seguridad. La explotación con éxito compromete la confidencialidad, integridad y disponibilidad del sistema objetivo. En el momento de la publicación de asesoramiento, no se conocía la explotación pública de esta vulnerabilidad de seguridad."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"productcert@siemens.com","type":"Secondary","description":[{"lang":"en","value":"CWE-285"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:siemens:siveillance_video_management_software_2017_r2:*:*:*:*:*:*:*:*","versionEndExcluding":"11.2a","matchCriteriaId":"57B38507-984D-40E9-A3A5-40B7BF29BDF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:siemens:siveillance_video_management_software_2018_r1:*:*:*:*:*:*:*:*","versionEndExcluding":"12.1a","matchCriteriaId":"323A9152-90F1-4222-8468-1C1843B30C21"},{"vulnerable":true,"criteria":"cpe:2.3:a:siemens:siveillance_video_management_software_2018_r2:*:*:*:*:*:*:*:*","versionEndExcluding":"12.2a","matchCriteriaId":"EA4F90DF-54F4-4757-BFBB-D3594B866B45"},{"vulnerable":true,"criteria":"cpe:2.3:a:siemens:siveillance_video_management_software_2018_r3:*:*:*:*:*:*:*:*","versionEndExcluding":"12.3a","matchCriteriaId":"CDA10332-9542-4C47-9870-BADDC276C160"},{"vulnerable":true,"criteria":"cpe:2.3:a:siemens:siveillance_video_management_software_2019_r1:*:*:*:*:*:*:*:*","versionEndExcluding":"13.1a","matchCriteriaId":"6A8464AB-5EC6-4147-90B2-19ED8FB3A4E4"}]}]}],"references":[{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-212009.pdf","source":"productcert@siemens.com","tags":["Patch","Vendor Advisory"]},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-19-162-01","source":"productcert@siemens.com","tags":["Third Party Advisory","US Government Resource"]},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-212009.pdf","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-19-162-01","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]}]}}]}