CVE-2023-30898
Last modified
CVE-2023-30898 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All versions < V21.2 HotfixRev8), Siveillance Video 2022 R1 (All versions < V22.1 HotfixRev7), Siveillance Video 2022 R2 (All versions < V22.2 HotfixRev5), Siveillance Video 2022 R3 (All versions < V22.3 HotfixRev2), Siveillance Video 2023 R1 (All versions < V23.1 HotfixRev1). The Event Server component of affected applications deserializes data without sufficient validations. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All versions < V21.2 HotfixRev8), Siveillance Video 2022 R1 (All versions < V22.1 HotfixRev7), Siveillance Video 2022 R2 (All versions < V22.2 HotfixRev5), Siveillance Video 2022 R3 (All versions < V22.3 HotfixRev2), Siveillance Video 2023 R1 (All versions < V23.1 HotfixRev1). The Event Server component of affected applications deserializes data without sufficient validations. This could allow an authenticated remote attacker to execute code on the affected system.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Siemens | Siveillance Video | 2020 | R2 |
| Siemens | Siveillance Video | 2021 | R1 |
| Siemens | Siveillance Video | 2022 | R1 |
| Siemens | Siveillance Video | 2023 | R1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-30898?
How severe is CVE-2023-30898?
How do I fix CVE-2023-30898?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-30875Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabili…4.8
- CVE-2023-30876Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabili…4.8
- CVE-2023-30877Unauth. Reflected Cross-Site Scripting (XSS) vulnerability i…6.1
- CVE-2023-3088The WP Mail Log plugin for WordPress is vulnerable to Stored…6.1
- CVE-2023-3089A compliance problem was found in the Red Hat OpenShift Cont…7.5
- CVE-2023-30897A vulnerability has been identified in SIMATIC WinCC (All ve…7.8
- CVE-2023-30899A vulnerability has been identified in Siveillance Video 202…8.8
- CVE-2023-3090A heap out-of-bounds write vulnerability in the Linux Kernel…7.8
- CVE-2023-30900A vulnerability has been identified in Xpedition Layout Brow…7.8
- CVE-2023-30901A vulnerability has been identified in SICAM P850 (7KG8500-0…8.8
- CVE-2023-30902A privilege escalation vulnerability in the Trend Micro Apex…5.5
- CVE-2023-30903HP-UX could be exploited locally to create a Denial of Servi…5.5
Are you affected by CVE-2023-30898?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
