Denial of Service Vulnerability in Desigo PX Automation Controllers by Siemens
CVE-2019-13927

5.3MEDIUM

Summary

A vulnerability exists in certain Desigo PX automation controllers and their web modules allowing a remote attacker to send specially crafted HTTP requests. This could result in a denial of service condition by causing the web server on the affected devices to respond with 404 errors to all incoming requests. Although the devices would remain operational, the web interface becomes inaccessible and would require a reboot to restore functionality.

Affected Version(s)

Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 All firmware versions < V6.00.320

Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U with Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 All firmware versions < V6.00.320

Desigo PX automation controllers PXC22.1-E.D, PXC36-E.D, PXC36.1-E.D with activated web server All firmware versions < V6.00.320

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.