← Back

CVE-2019-19282

nvd nist
Published: Mar 10, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD (Secondary)

Description

A vulnerability has been identified in OpenPCS 7 V8.1 (All versions), OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd3), SIMATIC BATCH V8.1 (All versions), SIMATIC BATCH V8.2 (All versions < V8.2 Upd12), SIMATIC BATCH V9.0 (All versions < V9.0 SP1 Upd5), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Update 1), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC Route Control V8.1 (All versions), SIMATIC Route Control V8.2 (All versions), SIMATIC Route Control V9.0 (All versions < V9.0 Upd4), SIMATIC WinCC (TIA Portal) V13 (All versions < V13 SP2), SIMATIC WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 10), SIMATIC WinCC (TIA Portal) V15.1 (All versions < V15.1 Update 5), SIMATIC WinCC (TIA Portal) V16 (All versions < V16 Update 1), SIMATIC WinCC V7.3 (All versions), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 14), SIMATIC WinCC V7.5 (All versions < V7.5 SP1 Update 1). Through specially crafted messages, when encrypted communication is enabled, an attacker with network access could use the vulnerability to compromise the availability of the system by causing a Denial-of-Service condition. Successful exploitation requires no system privileges and no user interaction.

Affected (44)

6 products
Openpcs 7
Simatic Batch
Simatic Net Pc
Simatic Pcs 7
Simatic Route Control
Simatic Wincc
Configuration A
44 vulnerable
Vulnerable SoftwareAffected Versions
Siemens
Version 9.0
Version 9.0_update_1
Siemens
Version 9.0
Version 9.0 sp1
Version 9.0 sp1_update_1
Version 9.0 sp1_update_2
Version 9.0 sp1_update_3
Version 9.0 sp1_update_4
Siemens
Before 16
Version 16
Siemens
Version 8.1
Version 8.2
Version 9.0
Version 9.0 sp1
Version 9.0 sp2
Siemens
Before 9.0
Version 9.0
Siemens
Version 13
Version 13 sp1
Version 14.0.1
Version 15.1
Version 15.1 update_1
Version 15.1 update_2
Version 15.1 update_3
Version 15.1 update_4
Version 16
Version 7.4
Version 7.4 sp1
Version 7.4 sp1_update_10
Version 7.4 sp1_update_11
Version 7.4 sp1_update_12
Version 7.4 sp1_update_13
Version 7.4 sp1_update_1
Version 7.4 sp1_update_2
Version 7.4 sp1_update_3
Version 7.4 sp1_update_4
Version 7.4 sp1_update_5
Version 7.4 sp1_update_6
Version 7.4 sp1_update_7
Version 7.4 sp1_update_8
Version 7.4 sp1_update_9
Version 7.5.1
Version 7.5
Version 7.5 sp1

References (2)

Source: productcert@siemens.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.