Denial of Service Vulnerability in Desigo PX Automation Controllers by Siemens
CVE-2019-13927
Key Information:
- Vendor
- Siemens Ag
- Status
- Desigo Px Automation Controllers Pxc00-e.d, Pxc50-e.d, Pxc100-e.d, Pxc200-e.d With Desigo Px Web Modules Pxa40-w0, Pxa40-w1, Pxa40-w2
- Desigo Px Automation Controllers Pxc00-u, Pxc64-u, Pxc128-u With Desigo Px Web Modules Pxa30-w0, Pxa30-w1, Pxa30-w2
- Desigo Px Automation Controllers Pxc22.1-e.d, Pxc36-e.d, Pxc36.1-e.d With Activated Web Server
- Vendor
- CVE Published:
- 12 December 2019
Summary
A vulnerability exists in certain Desigo PX automation controllers and their web modules allowing a remote attacker to send specially crafted HTTP requests. This could result in a denial of service condition by causing the web server on the affected devices to respond with 404 errors to all incoming requests. Although the devices would remain operational, the web interface becomes inaccessible and would require a reboot to restore functionality.
Affected Version(s)
Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 All firmware versions < V6.00.320
Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U with Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 All firmware versions < V6.00.320
Desigo PX automation controllers PXC22.1-E.D, PXC36-E.D, PXC36.1-E.D with activated web server All firmware versions < V6.00.320
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved