Denial of Service Vulnerability in Siemens SCALANCE Products
CVE-2019-19301
7.5HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 14 April 2020
Summary
A vulnerability has been discovered in several SCALANCE products by Siemens, where the VxWorks-based Profinet TCP Stack can incur significant processing overhead for each incoming packet. This can lead to a denial of service condition, compromising the availability and stability of the affected devices. Users and organizations employing these devices may face operational disruptions and should take immediate action to assess their vulnerability status.
Affected Version(s)
SCALANCE X200-4P IRT All versions < V5.5.0
SCALANCE X201-3P IRT All versions < V5.5.0
SCALANCE X201-3P IRT PRO All versions < V5.5.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved