Buffer Overflow Vulnerability in EN100 Ethernet Module by Siemens
CVE-2019-13942
Key Information:
- Vendor
Siemens Ag
- Status
- Vendor
- CVE Published:
- 12 December 2019
What is CVE-2019-13942?
A buffer overflow vulnerability in the Siemens EN100 Ethernet module affects all versions of several variants including DNP3, IEC 61850 (below v4.37), IEC104, Modbus TCP, and PROFINET IO. This vulnerability allows unauthorized users to exploit the webserver of the affected modules by sending specially crafted packets, potentially leading to a Denial-of-Service condition. If exploited, devices may require a manual restart for full recovery. At the time of advisory publication, there was no known public exploitation of this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EN100 Ethernet module DNP3 variant All versions
EN100 Ethernet module IEC 61850 variant All versions < V4.37
EN100 Ethernet module IEC104 variant All versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved