Denial of Service Vulnerability in Siemens SIMATIC Products
CVE-2019-13940
5.3MEDIUM
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 11 February 2020
What is CVE-2019-13940?
A vulnerability in Siemens SIMATIC products may be exploited by sending specially crafted HTTP requests to the web server, specifically targeting ports 80/tcp and 443/tcp. This could potentially lead to a denial of service situation, impacting the availability of the web service. It is important to note that no other functionalities or interfaces are affected by this condition, making mitigation crucial to ensure operational continuity.
Affected Version(s)
SIMATIC ET 200pro IM154-8 PN/DP CPU All versions < V3.X.17
SIMATIC ET 200pro IM154-8F PN/DP CPU All versions < V3.X.17
SIMATIC ET 200pro IM154-8FX PN/DP CPU All versions < V3.X.17