CVE-2019-10936
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD (Secondary)
Description
Affected devices improperly handle large amounts of specially crafted UDP packets.
This could allow an unauthenticated remote attacker to trigger a denial of service condition.
Affected (83)
Products: Siemens: Dk Standard Ethernet Controller Firmware, Ek Ertec 200 Firmware, Ek Ertec 200p Firmware, Simatic Cfu Pa Firmware, Simatic Et 200al Firmware, Simatic Et 200m Firmware, Simatic Et 200mp Im 155 5 Pn Ba Firmware, Simatic Et 200mp Im 155 5 Pn Hf Firmware, Simatic Et 200mp Im 155 5 Pn St Firmware, Simatic Et 200s Firmware, Simatic Et 200sp Im 155 6 Pn Ba Firmware, Simatic Et 200sp Im 155 6 Pn Ha Firmware, Simatic Et 200sp Im 155 6 Pn Hf Firmware, Simatic Et 200sp Im 155 6 Pn Hs Firmware, Simatic Et 200sp Im 155 6 Pn St Firmware, Simatic Et 200sp Im 155 6 Pn/2 Hf Firmware, Simatic Et 200sp Im 155 6 Pn/3 Hf Firmware, Simatic Et 200ecopn Firmware, Simatic Et 200pro Firmware, Simatic Hmi Comfort Outdoor Panels 7" Firmware, Simatic Hmi Comfort Outdoor Panels 15" Firmware, Simatic Hmi Comfort Panels 4" Firmware, Simatic Hmi Comfort Panels 22" Firmware, Simatic Hmi Ktp Mobile Panels Firmware, Simatic Pn/pn Coupler Firmware, Simatic Profinet Driver Firmware, Simatic S7 1200 Cpu Firmware, Simatic S7 1200 Cpu 1211c Firmware, Simatic S7 1200 Cpu 1212c Firmware, Simatic S7 1200 Cpu 1214c Firmware, Simatic S7 1500 Cpu Firmware, Simatic S7 1500s Cpu Firmware, Simatic S7 1500t Cpu Firmware, Simatic S7 1500 Cpu 1518 Firmware, Simatic S7 1500 Cpu 1511c Firmware, Simatic S7 1500 Cpu 1512c Firmware, Simatic S7 300 Cpu Firmware, Simatic S7 300 Cpu 312 Ifm Firmware, Simatic S7 300 Cpu 313 Firmware, Simatic S7 300 Cpu 314 Firmware, Simatic S7 300 Cpu 314 Ifm Firmware, Simatic S7 300 Cpu 315 Firmware, Simatic S7 300 Cpu 315 2 Dp Firmware, Simatic S7 300 Cpu 316 2 Dp Firmware, Simatic S7 300 Cpu 318 2 Firmware, Simatic S7 400 Pn V7 Firmware, Simatic S7 400 Dp V7 Firmware, Simatic S7 400 V6 Firmware, Simatic S7 400h V6 Firmware, Simatic S7 410 V8 Firmware, Simatic Winac Rtx (f) Firmware, Sinamics Dcm Firmware, Sinamics Dcp Firmware, Sinamics G110m Firmware, Sinamics G120 Firmware, Sinamics G130 Firmware, Sinamics G150 Firmware, Sinamics Gl150 Firmware, Sinamics Gm150 Firmware, Sinamics S110 Firmware, Sinamics S120 Firmware, Sinamics S150 Firmware, Sinamics Sl150 Firmware, Sinamics Sm120 Firmware, Sinumerik 828d, Sinumerik 840d Sl
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Dk Standard Ethernet Controller | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Ek Ertec 200 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.6 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ek Ertec 200p | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Cfu Pa | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200al | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200m | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.3.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200mp Im 155 5 Pn Ba | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200mp Im 155 5 Pn Hf | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200mp Im 155 5 Pn St | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200s | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200sp Im 155 6 Pn Ba | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200sp Im 155 6 Pn Ha | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.2.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200sp Im 155 6 Pn Hf | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200sp Im 155 6 Pn Hs | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200sp Im 155 6 Pn St | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.2.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200sp Im 155 6 Pn/2 Hf | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.2.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200sp Im 155 6 Pn/3 Hf | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200ecopn | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Et 200pro | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Hmi Comfort Outdoor Panels 7" | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Hmi Comfort Outdoor Panels 15" | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Hmi Comfort Panels 4" | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Hmi Comfort Panels 22" | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Hmi Ktp Mobile Panels | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.2.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Pn/pn Coupler | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Profinet Driver | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1200 Cpu | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1200 Cpu 1211c | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1200 Cpu 1212c | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1200 Cpu 1214c | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1500 Cpu | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1500s Cpu | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1500t Cpu | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1500 Cpu 1518 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1500 Cpu 1511c | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1500 Cpu 1512c | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 312 Ifm | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 313 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 314 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 314 Ifm | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 315 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 315 2 Dp | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 316 2 Dp | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 300 Cpu 318 2 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 400 Pn V7 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 400 Dp V7 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.0.9 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 400 V6 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.0.9 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 400h V6 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.2.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 410 V8 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2010 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Winac Rtx (f) 2010 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.5 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics Dcm | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.3 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics Dcp | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.7 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics G110m | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.7 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics G120 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics G130 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics G150 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.8 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics Gl150 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.8 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics Gm150 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics S110 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics S120 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics S150 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.7 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics Sl150 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinamics Sm120 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.8 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
References (4)
Source: productcert@siemens.com
Source: productcert@siemens.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.