CVE-2019-19300 Information
Description
A vulnerability has been identified in KTK ATE530S (All versions) SIDOOR ATD430W (All versions) SIDOOR ATE530S COATED (All versions) SIDOOR ATE531S (All versions) SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions V2.0) SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions V2.0) SIMATIC ET200MP IM155-5 PN HF (incl. SIPLUS variants) (All versions = V4.2) SIMATIC ET200SP IM155-6 MF HF (All versions) SIMATIC ET200SP IM155-6 PN HA (incl. SIPLUS variants) (All versions) SIMATIC ET200SP IM155-6 PN HF (incl. SIPLUS variants) (All versions = V4.2) SIMATIC ET200SP IM155-6 PN/2 HF (incl. SIPLUS variants) (All versions = V4.2) SIMATIC ET200SP IM155-6 PN/3 HF (incl. SIPLUS variants) (All versions = V4.2) SIMATIC MICRO-DRIVE PDC (All versions) SIMATIC PN/PN Coupler (incl. SIPLUS NET variants) (All versions = V4.2) SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions V2.0) SIMATIC S7-1500 Software Controller (All versions V2.0) SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions) SIMATIC S7-400 H V6 CPU family and below (incl. SIPLUS variants) (All versions) SIMATIC S7-400 PN/DP V7 and below CPU family (incl. SIPLUS variants) (All versions) SIMATIC S7-410 CPU family (incl. SIPLUS variants) (All versions) SIMATIC TDC CP51M1 (All versions) SIMATIC TDC CPU555 (All versions) SIMATIC WinAC RTX (F) 2010 (All versions) SINAMICS S/G Control Unit w. PROFINET (All versions). The Interniche-based TCP Stack can be forced to make very expensive calls for every incoming packet which can lead to a denial of service.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
https://cert-portal.siemens.com/productcert/pdf/ssa-593272.pdf https://www.us-cert.gov/ics/advisories/icsa-20-105-08
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Share on: