← Back

CVE-2019-10931

nvd nist
Published: Jul 11, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions ), DIGSI 5 engineering software (All versions < V7.90), SIPROTEC 5 device types 6MD85, 6MD86, 6MD89, 7UM85, 7SA87, 7SD87, 7SL87, 7VK87, 7SA82, 7SA86, 7SD82, 7SD86, 7SL82, 7SL86, 7SJ86, 7SK82, 7SK85, 7SJ82, 7SJ85, 7UT82, 7UT85, 7UT86, 7UT87 and 7VE85 with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions < V7.90), SIPROTEC 5 device types 7SS85 and 7KE85 (All versions < V8.01), SIPROTEC 5 device types with CPU variants CP200 and the respective Ethernet communication modules (All versions < V7.59), SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules (All versions < V7.59). Specially crafted packets sent to port 443/TCP could cause a Denial of Service condition.

Affected (3)

2 products
Siprotec 5 Digsi Device Driver
Digsi 5 Engineering Software
Configuration A
1 vulnerable · 24 platform
Vulnerable SoftwareAffected Versions
Before 7.90
Running on/withPlatform Versions
Siemens
6md85
All versions
Siemens
6md86
All versions
Siemens
6md89
All versions
Siemens
7sa82
All versions
Siemens
7sa86
All versions
Siemens
7sa87
All versions
Siemens
7sd82
All versions
Siemens
7sd86
All versions
Siemens
7sd87
All versions
Siemens
7sj82
All versions
Siemens
7sj85
All versions
Siemens
7sj86
All versions
Siemens
7sk82
All versions
Siemens
7sk85
All versions
Siemens
7sl82
All versions
Siemens
7sl86
All versions
Siemens
7sl87
All versions
Siemens
7um85
All versions
Siemens
7ut82
All versions
Siemens
7ut85
All versions
Siemens
7ut86
All versions
Siemens
7ut87
All versions
Siemens
7ve85
All versions
Siemens
7vk87
All versions
Configuration B
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 8.01
Running on/withPlatform Versions
Siemens
7ke85
All versions
Siemens
7ss85
All versions
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 7.90

References (2)

Source: productcert@siemens.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.