Denial of Service Vulnerability in Siemens Webserver Products
CVE-2019-6568

7.5HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
17 April 2019

Summary

A vulnerability exists in the webserver of certain Siemens devices that allows an attacker with network access to create a denial of service condition. This could lead to the webserver restarting, thereby interrupting service availability. No system privileges or user interaction are required for an attack, making the threat particularly concerning for operational continuity.

Affected Version(s)

SIMATIC CP 1604 All versions

SIMATIC CP 1616 All versions

SIMATIC CP 343-1 Advanced All versions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.