Denial of Service Vulnerability in Siemens SCALANCE Products
CVE-2019-19301

7.5HIGH

Key Information:

Summary

A vulnerability has been discovered in several SCALANCE products by Siemens, where the VxWorks-based Profinet TCP Stack can incur significant processing overhead for each incoming packet. This can lead to a denial of service condition, compromising the availability and stability of the affected devices. Users and organizations employing these devices may face operational disruptions and should take immediate action to assess their vulnerability status.

Affected Version(s)

SCALANCE X200-4P IRT All versions < V5.5.0

SCALANCE X201-3P IRT All versions < V5.5.0

SCALANCE X201-3P IRT PRO All versions < V5.5.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.