CVE Database
/

CVE-2023-30899

Back to search

CVE-2023-30899

Published: May 9, 2023

Modified: Jan 28, 2025

PUBLISHED

CVSS v3.1

9.9

CRITICAL

Description

A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All versions < V21.2 HotfixRev8), Siveillance Video 2022 R1 (All versions < V22.1 HotfixRev7), Siveillance Video 2022 R2 (All versions < V22.2 HotfixRev5), Siveillance Video 2022 R3 (All versions < V22.3 HotfixRev2), Siveillance Video 2023 R1 (All versions < V23.1 HotfixRev1). The Management Server component of affected applications deserializes data without sufficient validations. This could allow an authenticated remote attacker to execute code on the affected system.

VendorProductVersions

Siemens

Siveillance Video 2020 R2

affected
All versions < V20.2 HotfixRev14

Siemens

Siveillance Video 2020 R3

affected
All versions < V20.3 HotfixRev12

Siemens

Siveillance Video 2021 R1

affected
All versions < V21.1 HotfixRev12

Siemens

Siveillance Video 2021 R2

affected
All versions < V21.2 HotfixRev8

Siemens

Siveillance Video 2022 R1

affected
All versions < V22.1 HotfixRev7

Siemens

Siveillance Video 2022 R2

affected
All versions < V22.2 HotfixRev5

Siemens

Siveillance Video 2022 R3

affected
All versions < V22.3 HotfixRev2

Siemens

Siveillance Video 2023 R1

affected
All versions < V23.1 HotfixRev1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now