← Back

CVE-2019-13927

nvd nist
Published: Dec 12, 2019Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U with Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC22.1-E.D, PXC36-E.D, PXC36.1-E.D with activated web server (All firmware versions < V6.00.320). The device contains a vulnerability that could allow an attacker to cause a denial of service condition on the device's web server by sending a specially crafted HTTP message to the web server port (tcp/80). The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the device's web service. While the device itself stays operational, the web server responds with HTTP status code 404 (Not found) to any further request. A reboot is required to recover the web interface. At the time of advisory publication no public exploitation of this security vulnerability was known.

Affected (16)

16 products
Pxc00 E.d Firmware
Pxc50 E.d Firmware
Pxc100 E.d Firmware
Pxc200 E.d Firmware
Pxa40 W0 Firmware
Pxa40 W1 Firmware
Pxa40 W2 Firmware
Pxc00 U Firmware
Pxc64 U Firmware
Pxc128 U Firmware
Pxa30 W0 Firmware
Pxa30 W1 Firmware
Pxa30 W2 Firmware
Pxc22.1 E.d Firmware
Pxc36 E.d Firmware
Pxc36.1 E.d Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxc00 E.d
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxc50 E.d
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxc100 E.d
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxc200 E.d
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxa40 W0
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxa40 W1
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxa40 W2
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxc00 U
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxc64 U
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxc128 U
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxa30 W0
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxa30 W1
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxa30 W2
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxc22.1 E.d
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxc36 E.d
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.00.320
Running on/withPlatform Versions
Siemens
Pxc36.1 E.d
All versions

References (2)

Source: productcert@siemens.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.