CVE-2019-6568
7.5HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 17 April 2019
Summary
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device.
The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the device.
Affected Version(s)
SIMATIC CP 1604 All versions
SIMATIC CP 1616 All versions
SIMATIC CP 343-1 Advanced All versions
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved