Denial of Service Vulnerability in Siemens Webserver Products
CVE-2019-6568
7.5HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 17 April 2019
Summary
A vulnerability exists in the webserver of certain Siemens devices that allows an attacker with network access to create a denial of service condition. This could lead to the webserver restarting, thereby interrupting service availability. No system privileges or user interaction are required for an attack, making the threat particularly concerning for operational continuity.
Affected Version(s)
SIMATIC CP 1604 All versions
SIMATIC CP 1616 All versions
SIMATIC CP 343-1 Advanced All versions
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved