CVE-2019-10923
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD (Secondary)
Description
An attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IRT) of the affected installation.
Affected (60)
Products: Siemens: Cp1604 Firmware, Cp1616 Firmware, Dk Standard Ethernet Controller Firmware, Ek Ertec 200 Firmware, Ek Ertec 200p Firmware, Scalance X 200irt Firmware, Simatic Et 200m Firmware, Simatic Et 200s Firmware, Simatic Et 200ecopn Firmware, Simatic Pn/pn Coupler 6es7158 3ad01 0xa0 Firmware, Simatic S7 300 Cpu Firmware, Simatic S7 300 Cpu 312 Ifm Firmware, Simatic S7 300 Cpu 313 Firmware, Simatic S7 300 Cpu 314 Firmware, Simatic S7 300 Cpu 314 Ifm Firmware, Simatic S7 300 Cpu 315 Firmware, Simatic S7 300 Cpu 315 2 Dp Firmware, Simatic S7 300 Cpu 316 2 Dp Firmware, Simatic S7 300 Cpu 318 2 Firmware, Simatic S7 400 V6 Firmware, Simatic S7 400 Pn V7 Firmware, Simatic S7 400 Dp V7 Firmware, Simatic Winac Rtx (f) Firmware, Simotion Firmware, Sinamics Dcm Firmware, Sinamics Dcp Firmware, Sinamics G110m Firmware, Sinamics G120 Firmware, Sinamics G130 Firmware, Sinamics G150 Firmware, Sinamics Gh150 Firmware, Sinamics Gl150 Firmware, Sinamics Gm150 Firmware, Sinamics S110 Firmware, Sinamics S120 Firmware, Sinamics S150 Firmware, Sinamics Sl150 Firmware, Sinamics Sm120 Firmware, Sinumerik 828d, Sinumerik 840d Sl
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8 |
| Running on/with | Platform Versions |
|---|---|
Siemens Cp1604 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8 |
| Running on/with | Platform Versions |
|---|---|
Siemens Cp1616 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Dk Standard Ethernet Controller | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.5.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ek Ertec 200 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.5.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ek Ertec 200p | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.2.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X 200irt | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200m | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200s | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200ecopn | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Pn/pn Coupler 6es7158 3ad01 0xa0 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 312 Ifm | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 313 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 314 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 314 Ifm | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 315 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 315 2 Dp | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 316 2 Dp | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 318 2 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 400 V6 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 400 Pn V7 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 400 Dp V7 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2010 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Winac Rtx (f) | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simotion | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.5 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics Dcm | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.3 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics Dcp | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.7 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics G110m | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.7 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics G120 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.7 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics G130 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.8 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics G150 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.8 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics Gh150 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.8 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics Gl150 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.8 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics Gm150 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics S110 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.7 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics S120 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.8 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics S150 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.7 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics Sl150 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics Sm120 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.8 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
References (3)
Source: productcert@siemens.com
Source: productcert@siemens.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.