Denial of Service Vulnerability in Siemens SIMATIC Products
CVE-2019-13940

5.3MEDIUM

Summary

A vulnerability in Siemens SIMATIC products may be exploited by sending specially crafted HTTP requests to the web server, specifically targeting ports 80/tcp and 443/tcp. This could potentially lead to a denial of service situation, impacting the availability of the web service. It is important to note that no other functionalities or interfaces are affected by this condition, making mitigation crucial to ensure operational continuity.

Affected Version(s)

SIMATIC ET 200pro IM154-8 PN/DP CPU All versions < V3.X.17

SIMATIC ET 200pro IM154-8F PN/DP CPU All versions < V3.X.17

SIMATIC ET 200pro IM154-8FX PN/DP CPU All versions < V3.X.17

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.