Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-30899


A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All versions < V21.2 HotfixRev8), Siveillance Video 2022 R1 (All versions < V22.1 HotfixRev7), Siveillance Video 2022 R2 (All versions < V22.2 HotfixRev5), Siveillance Video 2022 R3 (All versions < V22.3 HotfixRev2), Siveillance Video 2023 R1 (All versions < V23.1 HotfixRev1). The Management Server component of affected applications deserializes data without sufficient validations. This could allow an authenticated remote attacker to execute code on the affected system.


Published

2023-05-09T13:15:18.183

Last Modified

2024-11-21T08:01:01.803

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.9 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens siveillance_video 2020 Yes
Application siemens siveillance_video 2020 Yes
Application siemens siveillance_video 2021 Yes
Application siemens siveillance_video 2021 Yes
Application siemens siveillance_video 2022 Yes
Application siemens siveillance_video 2022 Yes
Application siemens siveillance_video 2022 Yes
Application siemens siveillance_video 2023 Yes

References