CVE-2019-19297: Siemens Sinvr 3 Central Control Server

High severity, CVSS 7.5. EPSS: 2.8% chance of exploitation in the next 30 days.

A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server contains a path traversal vulnerability, that could allow an unauthenticated remote attacker to access and download arbitrary files from the server.

Affected products

  • Siemens Sinvr 3 Central Control Server: any version
  • Siemens Sinvr 3 Video Server: any version

Published 2020-03-10. Last modified 2026-06-17.