{
    "data_version": "4.0",
    "data_type": "CVE",
    "data_format": "MITRE",
    "CVE_data_meta": {
        "ID": "CVE-2019-18340",
        "ASSIGNER": "productcert@siemens.com",
        "STATE": "PUBLIC"
    },
    "description": {
        "description_data": [
            {
                "lang": "eng",
                "value": "A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), Control Center Server (CCS) (All versions >= V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0). Both the SiVMS/SiNVR Video Server and the Control Center Server (CCS) store\nuser and device passwords by applying weak cryptography.\n\nA local attacker could exploit this vulnerability to extract\nthe passwords from the user database and/or the device configuration files\nto conduct further attacks."
            }
        ]
    },
    "problemtype": {
        "problemtype_data": [
            {
                "description": [
                    {
                        "lang": "eng",
                        "value": "CWE-327: Use of a Broken or Risky Cryptographic Algorithm",
                        "cweId": "CWE-327"
                    }
                ]
            }
        ]
    },
    "affects": {
        "vendor": {
            "vendor_data": [
                {
                    "vendor_name": "Siemens",
                    "product": {
                        "product_data": [
                            {
                                "product_name": "Control Center Server (CCS)",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_affected": "=",
                                            "version_value": "All versions < V1.5.0"
                                        },
                                        {
                                            "version_affected": "=",
                                            "version_value": "All versions >= V1.5.0"
                                        }
                                    ]
                                }
                            },
                            {
                                "product_name": "SiNVR/SiVMS Video Server",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_affected": "=",
                                            "version_value": "All versions < V5.0.0"
                                        },
                                        {
                                            "version_affected": "=",
                                            "version_value": "All versions >= V5.0.0"
                                        }
                                    ]
                                }
                            }
                        ]
                    }
                }
            ]
        }
    },
    "references": {
        "reference_data": [
            {
                "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-761617.pdf",
                "refsource": "MISC",
                "name": "https://cert-portal.siemens.com/productcert/pdf/ssa-761617.pdf"
            },
            {
                "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-761844.pdf",
                "refsource": "MISC",
                "name": "https://cert-portal.siemens.com/productcert/pdf/ssa-761844.pdf"
            }
        ]
    },
    "impact": {
        "cvss": [
            {
                "version": "3.1",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM"
            }
        ]
    }
}